FScan is an open-source intranet network scanning utility written in Go that is frequently used during post-compromise operations for internal reconnaissance. It is designed to enumerate hosts, identify open ports, and gather service information across IP subnets, making it useful for mapping reachable systems and selecting targets for lateral movement. In observed intrusions, operators have used FScan to search for open ports, discover SMB-exposed systems, and support pivoting decisions after gaining an initial foothold.
The tool is not a bespoke malware family but a publicly available offensive utility that has been repeatedly incorporated into intrusion toolchains by multiple threat actors, including Chinese-speaking and China-linked clusters. Reported users include UAT-7237 in compromises of Taiwanese web infrastructure, CL-STA-0969 in telecommunications intrusions in Southwest Asia, and other actors targeting MS-SQL servers, South Korean web servers, and environments affected by exploitation of Ivanti Connect Secure vulnerabilities. In several cases, FScan was staged on compromised hosts alongside proxies, remote-access tools, credential theft utilities, and privilege-escalation tooling, underscoring its role in hands-on-keyboard post-exploitation rather than initial compromise.
Observed deployment methods include direct transfer to compromised systems and execution through DLL side-loading or fileless loaders to reduce detection. FScan has been used primarily on Windows systems in the cited intrusions, although its role is consistently that of a reconnaissance and network-discovery aid rather than a persistence or command-and-control implant. Its repeated appearance across espionage and financially motivated operations reflects its utility as a lightweight scanner for internal network visibility and attack-path development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Fscan tool has also been uploaded to the download server; it appears that threat actors can use it to scan internal networks as needed to identify Attack Targets for lateral movement.
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
"For its network-scanning activities, UAT-7237 uses FScan to search for open ports..."
The threat actor has also been observed deploying a SOCKS proxy on compromised servers to launch scans for internal reconnaissance and lateral movement using open-source tools like Fscan.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK® Tactic Technique ID ... Remote System / Account Discovery T1018 / T1033
According to the timeline of the detection logs, the attackers were able to leverage some of these web shells to execute commands on the affected server and drop more post-exploitation tools utilized for lateral movement.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network scanning tool used to identify internal targets for lateral movement.
An open-source network scanning/reconnaissance tool used by the operators for internal reconnaissance and to support lateral movement activities after compromise.
Network scanning tool used to identify open ports/services and support lateral movement discovery.
Network scanning utility used to identify reachable hosts and open ports for follow-on lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.