ScanBox is a PHP- and JavaScript-based reconnaissance and surveillance framework documented since at least 2014 and used by multiple China-linked cyberespionage groups. Its client-side components execute in victims’ browsers, enabling information collection without installing a conventional endpoint executable. It is used primarily for pre-compromise profiling and browser-based surveillance and has appeared in campaigns alongside browser exploitation frameworks and follow-on malware.
ScanBox uses a modular architecture to collect browser and operating-system information, installed browser plugins, page metadata, language settings, screen characteristics, and cookies. Its plugins support browser fingerprinting, security-software detection, WebRTC-based peer connectivity, and keylogging. Captured information and keystrokes are transmitted to attacker-controlled infrastructure. In an observed implementation, the keylogger captured input within an iframe created by the framework. Deployments on compromised VPN login portals have supported credential and cookie theft.
Delivery commonly involves JavaScript injected into compromised websites, watering-hole redirects, and phishing links to attacker-controlled pages impersonating legitimate publications or application stores. ScanBox has also been retrieved by the FriarFox malicious Firefox extension. Associated actors include TA413, APT3, APT27/LuckyMouse, APT40, and Earth Empusa. Campaigns involving the framework have targeted Tibetan and Uyghur communities, government organizations, Japanese high-technology organizations, Australian media, and heavy-industry and energy-related organizations operating around the South China Sea.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"The JavaScript in these attacks links back to a JavaScript profiling and exploitation framework called Scanbox."
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FriarFox ... contacted command-and-control infrastructure associated with the Javascript reconnaissance framework Scanbox.
Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.
Upon continued investigation in late April 2020, we found another phishing page that appears to be copied from a third-party web store and injected with two scripts to load ScanBox and BeEF frameworks.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
"...redirected users to malicious sites hosting exploitation tools such as ScanBox and BEeF (Browser Exploitation Framework)."
Proofpoint and PwC Threat Intelligence have jointly identified a cyber espionage campaign, active since April 2022 through June, delivering the ScanBox exploitation framework to targets who visit a malicious domain posing as an Australian news website.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious URLs provided in the emails also appear to use values that are customized for each target... the number string that follows it... appears to be a unique identifier for each recipient... This may be an attempt by the threat actor to correlate traffic to its servers... with custom user identifiers which targets received within the URLs via email.
“A watering hole attack is a cybersecurity strategy where attackers compromise a website or service frequently visited by a specific target group. The attackers infect the website with malware to gain access to the visitors' systems.”
“It appears to have started with CVE-2014-3393, a vulnerability in… the Cisco Clientless SSL VPN portal… [allowing] an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal…”
Beginning on 12 April 2022, and continuing through mid-June 2022, Proofpoint identified several waves of a phishing campaign... The phishing campaign involved URLs delivered in phishing emails, which redirected victims to a malicious website posing as an Australian news media outlet.
“The file 1.js was a variant of an online script called ‘xss.js’ that was designed to steal form data.”
Every 30 seconds, ActionSpy will collect basic device information like IMEI, phone number, manufacturer, battery status, etc., which it sends to the C&C server as a heartbeat request.
Victim browser plugins Identification: This plugin gathers the name, filename, and description of any legitimate browser plugin installed in the victim’s browser... Browser fingerprinting plugin... checks whether Java is installed, and if so what version; The version of ActiveX installed; Whether specific Java web applications are installed...
“The file 1.js was a variant of an online script called ‘xss.js’ that was designed to steal form data.”
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
“Attackers have been able to successfully implant JavaScript code on the login pages that enables them to surreptitiously steal employee credentials as they login…”
The initial script harvests several types of information from visitors... Sending Information about the victim’s browser back to the C2, including: Version of Flash installed; Location; Referrer; User-Agent; Cookie; Character encoding; Screen width and height; Underlying Operating System; Language; Screen’s colour depth.
The modular ScanBox architecture works by sending data to different responsive PHP scripts hosted on a same server-side folder... /i/v.php?m=b Send victim information back to the C2 ... /i/v.php?m=plug URL that plugins send gathered data back to
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A framework delivered through compromised religious and charitable websites in the 2019 Holy Water watering-hole campaign to collect extensive information from infected users, including browsing habits and other sensitive data.
A JavaScript reconnaissance framework mentioned in the historical account of TA413's FriarFox campaigns. The report links FriarFox communications to Scanbox-associated infrastructure but does not detail Scanbox's execution or capabilities in those campaigns.
JavaScript-based web reconnaissance and exploitation framework used to profile victims in the browser, fingerprint systems, collect browser and host data, load modular plugins, keylog keystrokes in iframes, identify browser plugins, perform browser fingerprinting, and support follow-on exploitation or compromise.
Scanbox is a reconnaissance and keylogging framework used for tracking website visitors, collecting user data, and performing keylogging. It is delivered via browser-based attacks, often as a second-stage payload after initial compromise (e.g., via FriarFox). It is used for espionage and surveillance, particularly against dissident and ethnic minority groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.