Tool
SoftPerfect Network Scanner
- First Reported
- Aug 5, 2025
- Latest Reported
- Sep 1, 2026
Reported Context (6)
- the threat actors used Advanced IP Scanner to enumerate the network. In one incident, SoftPerfect Network Scanner was executed multiple times across numerous servers in preparation for lateral movement and Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook
- actor again logged into the domain controller, executed discovery commands, and then dropped a SoftPerfect Network Scanner binary (n.exe), which was executed to perform a network scan. Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions
- Softperfect Network Scanner continues to be a favored tool in this and many other intrusions we observe. EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment
- They then expanded their activity to network-wide enumeration by deploying SoftPerfect Network Scanner (netscan). Lynx Ransomware Attack Began with Compromised RDP Credentials
- They leveraged various tools such as AdFind, SharpHound, SoftPerfect NetScan, and GT_NET.exe (Grixba) to map out the environment and perform reconnaissance activities. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (2)
Malware (11)
People (16)
Threat Actors (4)
MITRE ATT&CK (70)
Vendors (13)
Products (31)
Tools (29)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.