fscan is an open-source, dual-use internal-network reconnaissance, vulnerability-scanning, and brute-force tool used in penetration testing and malicious post-compromise operations. It runs on Windows and Linux and supports host enumeration, open-port discovery across IP subnets, vulnerability identification, and authentication brute forcing. Attackers use it to map compromised environments, identify reachable services and potential attack targets, and support lateral movement, including attempts using previously obtained passwords. It is a scanning utility rather than a dedicated malware implant.
Observed deployments include intrusions involving ExCobalt, Earth Lamia, Earth Krahang, UAT-7237, UAT-9921, and Feral Wolf. Its use spans espionage, cryptomining, and ransomware operations affecting government, telecommunications, web-hosting, healthcare, financial services, and other enterprise environments. Operators commonly introduce fscan after gaining access to a server, sometimes alongside web shells, remote-access implants, or proxy tools that provide connectivity to internal networks. It has been deployed following exploitation of vulnerable public-facing Confluence and WSO2 servers. These entry methods belong to the surrounding intrusion chains, not to an intrinsic distribution mechanism of fscan. Its public availability and use by numerous unrelated actors make its presence alone insufficient for threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Detection feedback ... also showed the installation of malware such as Cobalt Strike beacon for Windows ... and hacktool fscan ... especially in Windows environments.”
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
fscan was used to attempt lateral movement using the blasted passwords.
Scanning the network using tools like "Fscan" and "Kscan".
They conducted host and network reconnaissance using cat /etc/hosts, ls -anl /, netstat -an | grep EST and FScan from /var/tmp.
The Fscan tool has also been uploaded to the download server; it appears that threat actors can use it to scan internal networks as needed to identify Attack Targets for lateral movement.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The NAS build is written in Go and does much more. It scans internal and external networks and runs recon tools like fscan, ksubdomain, and httpx.
Fscan was executed from the var/tmp directory with the file name f and performed scanning to enumerate systems present within the environment.
MITRE ATT&CK® Tactic Technique ID ... Remote System / Account Discovery T1018 / T1033
Depuis le conteneur, ils ont effectué de la reconnaissance réseau et découvert un service PostgreSQL ... Outil de reconnaissance réseau : fscan.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Network reconnaissance and scanning tool used during post-compromise activity.
Network-scanning utility included in the campaign IOC list; its use is not further described.
Named offensive network-scanning tool identified among the campaign artifacts. The content provides its executable hash but does not describe its specific execution, scan results, or configuration.
A network scanning tool used to identify internal targets for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.