SCOUTCURL is a PowerShell-based reconnaissance and data-theft tool associated with Sandworm, including activity tracked by CERT-UA as UAC-0145. It has been observed in campaigns targeting Ukraine, particularly in 2026 operations that used ClickFix-style social engineering on compromised websites. In those intrusions, victims were tricked into executing malicious PowerShell commands from fake CAPTCHA or verification pages, after which SCOUTCURL could be deployed alongside other Sandworm tooling such as GHETTOVIBE, FLUIDLEECH, LOADLOOP, and the FREAKYPOLL backdoor.
SCOUTCURL performs basic host reconnaissance by collecting information about the operating system, installed software, files present on the system, and browser-related data. It then exfiltrates the harvested information to attacker-controlled infrastructure. Its role in the intrusion chain appears to be victim profiling and environment assessment, helping operators determine whether a compromised machine is of sufficient value for follow-on payloads and longer-term access.
The malware has been reported as part of broader Sandworm tradecraft that combines social engineering, compromised web infrastructure, and staged deployment of multiple payloads. SCOUTCURL specifically targets Windows environments through PowerShell execution and supports post-compromise reconnaissance and data collection in support of subsequent operations against sensitive Ukrainian organizations and networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Meanwhile, the SCOUTCURL PowerShell script has been collecting information about the operating system, installed software, files, and browser data and exfiltrating the data to the attackers’ infrastructure.
The same reporting also mentions SCOUTCURL, a PowerShell script used for basic system reconnaissance...
На наступному етапі ... може бути довантажений програмний засіб SCOUTCURL, що є PowerShell-сценарієм, який здійснює базову розвідку збираючи та ексфільтруючи інформацію про комп'ютер
11 distinct techniques documented for this family, organized by ATT&CK tactic.
the SCOUTCURL PowerShell script has been collecting information about the operating system, installed software, files, and browser data
SCOUTCURL software tool can be loaded onto the attacked computer... collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell-based reconnaissance and data theft tool that collects OS, software, file, and browser information and exfiltrates it to attacker infrastructure.
A PowerShell reconnaissance script used to collect basic infected-system details after initial compromise.
A PowerShell reconnaissance tool used to harvest basic details about an infected machine.
Reconnaissance tool observed in Sandworm operations against Ukrainian targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.