Advanced IP Scanner is a legitimate network scanning and host discovery utility that appears in multiple intrusion and ransomware investigations as a dual-use tool for internal reconnaissance and network mapping. In the cited incidents, attackers used it to identify other devices of interest on the same subnet, enumerate available network hosts, and support broader discovery activity. It was observed in operations associated with the Mad Liberator ransomware group, where it was used after access via abused AnyDesk sessions to identify potentially interesting devices on the victim subnet. It was also reported in activity involving the hacktivist/destructive group Twelve, alongside tools such as Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, and PsExec, for credential theft, discovery, network mapping, and privilege escalation. Additional reporting noted attackers dropping a file masquerading as SoftPerfect Network Scanner that was actually Advanced IP Scanner, and listed it among tools seen in Akira ransomware campaign activity targeting SonicWall SSL VPN environments. The content does not provide unique malware-style persistence or payload behavior for Advanced IP Scanner itself; rather, it is consistently described as a legitimate scanner abused by threat actors for active scanning and host enumeration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attacker then used Advanced IP Scanner to determine if there were other devices of interest that could be exploited within the same subnet.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools such as ADFind and Advanced IP Scanner, for example, are widely used for network and Active Directory administration but can also be abused to aid in reconnaissance.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used for internal network enumeration/port scanning during the second phase of the intrusion to support lateral movement and targeting prior to ransomware deployment.
A network scanning tool abused by the attacker to identify other potentially interesting devices on the local subnet during the intrusion.
Legitimate network scanning utility used by the intruder for network service discovery during post-compromise discovery.
Network scanning tool used to discover hosts and services in victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.