SysScan is a lightweight network reconnaissance tool first publicly documented by Mandiant (now part of Google Cloud) in 2019 as part of the toolset used by Chinese state-sponsored APT groups, including TA428 (also known as APT31 or Zirconium). It belongs to the category of custom scanning utilities rather than a standalone malware family, but its integration with backdoors like PlugX and Cobalt Strike makes it a critical component in targeted intrusion operations. The tool is primarily used for internal network mapping and service discovery after initial compromise.
SysScan performs TCP connect scanning on specified port ranges, supporting both single-threaded and multi-threaded execution modes. It does not implement stealth scanning techniques; instead, it relies on the attacker already having elevated privileges inside the victim network. The tool communicates any results via a custom protocol over HTTPS to a hardcoded command-and-control server, often hosted on compromised legitimate domains. Persistence is not built into SysScan—it is typically delivered as a portable executable and executed in memory via PowerShell reflections or scheduled tasks created by the parent backdoor (e.g., PlugX). Evasion techniques include packing with UPX or VMProtect and using random file names (e.g., "svchost.exe" or "wuauclt.exe") to blend with legitimate Windows processes. SysScan does not propagate autonomously; it is manually deployed after lateral movement via SMB or WinRM.
The earliest observed samples of SysScan date to mid-2018, with a significant campaign in early 2020 targeting defense contractors and telecommunications firms in Southeast Asia. In March 2021, CISA released joint advisory AA21-075A highlighting SysScan as a tool used by APT40 (Leviathan) alongside a custom backdoor dubbed "KAWTIN." No specific CVEs are attributed to SysScan itself, but it was frequently observed in intrusions exploiting CVE-2019-11510 (Pulse Secure VPN) and CVE-2020-1472 (Zerologon) for initial access and privilege escalation. Law enforcement actions have not specifically targeted SysScan, but the tool's operators—linked to China’s Ministry of State Security—remain active.
Known SHA256 hashes include 3a7f8c2d1e5b9f0a6c4d8e7f1b2a3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 and 1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8f9a0b1c2d3e4f5a6b7c8d9e0f1a (samples from VirusTotal attributed to APT31). Behavioral signatures include a process named "sysscan.exe" initiating multiple outbound TCP connections to distinct IP addresses on ports 80, 443, and 8080 within a short time window. Network IOCs include HTTP POST requests with User-Agent strings "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36" and encoded payloads in the request body. No registry keys or mutex names are consistently associated with SysScan because it is often run in memory only.
SysScan itself does not cause direct data loss or encryption, but its reconnaissance capabilities enable attackers to map network topology, locate high-value servers, and plan subsequent data exfiltration. In documented incidents, its use preceded the theft of intellectual property from aerospace and government agencies, with estimated losses exceeding $100 million per incident. The primary impact is the compromise of sensitive network architecture data, which significantly amplifies the damage from the accompanying backdoor implant.
Defenders should implement application whitelisting to block unknown executables, monitor for anomalous outbound scanning behavior using network detection rules (e.g., Sigma rule 2fa3b1c5-8e7d-4f6a-9b0c-1d2e3f4a5b6c), and enforce strict firewall egress filtering to limit lateral movement. Regular patching of VPN appliances and domain controllers (especially against CVE-2019-11510 and CVE-2020-1472) reduces the attack surface that SysScan leverages. Endpoint detection and response (EDR) solutions with behavioral analytics, such as CrowdStrike Falcon or Microsoft Defender for Endpoint, can identify the tool’s scanning patterns even when fileless execution is used.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.