ScanBox is a PHP- and JavaScript-based web reconnaissance and exploitation framework used primarily in cyber-espionage operations. Public reporting has documented its use since at least 2014, and it is widely assessed to be shared across multiple China-aligned threat groups rather than tied to a single operator. Reported users include APT3, LuckyMouse/APT27/Threat Group 3390, TA413, TA423/APT40/Leviathan, and Earth Empusa.
ScanBox is typically deployed through strategic web compromise, watering-hole operations, or phishing-linked lure sites that deliver malicious JavaScript to visitors in the browser. It has also been observed injected into compromised web portals, including Cisco ASA clientless SSL VPN login pages, where it was used to steal credentials and session material from users authenticating to enterprise remote-access infrastructure. Because it operates through browser-delivered scripts, it can support a largely fileless approach to victim profiling and collection.
Its core purpose is pre-compromise reconnaissance and victim selection, though some campaigns also used it alongside browser exploitation tooling. Documented capabilities include browser and host profiling, browser fingerprinting, plugin and software enumeration, keylogging, collection of cookies and other session-related data, and transmission of harvested information back to attacker infrastructure. Some observed modules also used WebRTC-based peer connection functionality and performed checks for security software. In multiple campaigns, ScanBox was used to identify high-value victims before follow-on exploitation or malware delivery, and in some cases it was paired with frameworks such as BeEF or used in intrusion chains that led to deployment of implants such as HyperBro.
Victimology associated with ScanBox spans government, media, academia, NGOs, high technology, manufacturing, energy, and dissident communities, with repeated targeting connected to Australian interests, Japanese organizations, Central Asian government infrastructure, Tibetan and Uyghur communities, and South China Sea-related entities. Its long-running use across espionage campaigns makes it a notable browser-based reconnaissance platform in the China-linked threat ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"The JavaScript in these attacks links back to a JavaScript profiling and exploitation framework called Scanbox."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.
Upon continued investigation in late April 2020, we found another phishing page that appears to be copied from a third-party web store and injected with two scripts to load ScanBox and BeEF frameworks.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
"...redirected users to malicious sites hosting exploitation tools such as ScanBox and BEeF (Browser Exploitation Framework)."
Proofpoint and PwC Threat Intelligence have jointly identified a cyber espionage campaign, active since April 2022 through June, delivering the ScanBox exploitation framework to targets who visit a malicious domain posing as an Australian news website.
Proofpoint and PwC Threat Intelligence have jointly identified a cyber espionage campaign, active since April 2022 through June, delivering the ScanBox exploitation framework to targets who visit a malicious domain posing as an Australian news website.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious URLs provided in the emails also appear to use values that are customized for each target... the number string that follows it... appears to be a unique identifier for each recipient... This may be an attempt by the threat actor to correlate traffic to its servers... with custom user identifiers which targets received within the URLs via email.
JavaScript - Individual Risks ... Drive-by-exploitation still a topic in 2015 ... Great Cannon: Easier than Man-on-the-side
“It appears to have started with CVE-2014-3393, a vulnerability in… the Cisco Clientless SSL VPN portal… [allowing] an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal…”
Beginning on 12 April 2022, and continuing through mid-June 2022, Proofpoint identified several waves of a phishing campaign... The phishing campaign involved URLs delivered in phishing emails, which redirected victims to a malicious website posing as an Australian news media outlet.
“The file 1.js was a variant of an online script called ‘xss.js’ that was designed to steal form data.”
Every 30 seconds, ActionSpy will collect basic device information like IMEI, phone number, manufacturer, battery status, etc., which it sends to the C&C server as a heartbeat request.
Victim browser plugins Identification: This plugin gathers the name, filename, and description of any legitimate browser plugin installed in the victim’s browser... Browser fingerprinting plugin... checks whether Java is installed, and if so what version; The version of ActiveX installed; Whether specific Java web applications are installed...
“The file 1.js was a variant of an online script called ‘xss.js’ that was designed to steal form data.”
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
“Attackers have been able to successfully implant JavaScript code on the login pages that enables them to surreptitiously steal employee credentials as they login…”
The initial script harvests several types of information from visitors... Sending Information about the victim’s browser back to the C2, including: Version of Flash installed; Location; Referrer; User-Agent; Cookie; Character encoding; Screen width and height; Underlying Operating System; Language; Screen’s colour depth.
The modular ScanBox architecture works by sending data to different responsive PHP scripts hosted on a same server-side folder... /i/v.php?m=b Send victim information back to the C2 ... /i/v.php?m=plug URL that plugins send gathered data back to
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript-based web reconnaissance and exploitation framework used to profile victims in the browser, fingerprint systems, collect browser and host data, load modular plugins, keylog keystrokes in iframes, identify browser plugins, perform browser fingerprinting, and support follow-on exploitation or compromise.
Scanbox is a reconnaissance and keylogging framework used for tracking website visitors, collecting user data, and performing keylogging. It is delivered via browser-based attacks, often as a second-stage payload after initial compromise (e.g., via FriarFox). It is used for espionage and surveillance, particularly against dissident and ethnic minority groups.
Reconnaissance framework leveraged to capture keystrokes.
JavaScript-based reconnaissance framework used on compromised or phishing pages to profile visitors, harvest browser and OS information, and record keypresses to support later-stage attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.