scanbox
- First seen
- 2014-06-01 00:00:00
- Malware type
- exploit-kit
- Family
- Malware family
- Profile updated
- 2026-07-07 12:53:09
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:cn country_code:hk country_code:us
Context
ScanBox is a reconnaissance and exploitation framework used in watering hole attacks, often targeting media and government sectors. It collects information on targeted systems and users, typically seen in campaigns by China-based threat actors.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Scanbox_Framework_Not_Obfuscated (yara-rule)
- SEKOIA_Apt_Scanbox_Obfuscated_Versions (yara-rule)
Reports & references
- secureworks.com — Bronze Mohawk (report)
- proofpoint.com — Chasing Currents Espionage South China Sea (report)
- proofpoint.com — Ta413 Leverages New Friarfox Browser Extension Target Gmail Accounts Global (report)
- volexity.com — Digital Crackdown Large Scale Surveillance And Exploitation Of Uyghurs (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Scanbox (report)
- alienvault.com — Scanbox A Reconnaissance Framework Used On Watering Hole Attacks (report)
- trustwave.com — Attacker Tracking Users Seeking Pakistani Passport (report)
- nattothoughts.substack.com — Reconnaissance Scanning Tools Used (report)
- resources.infosecinstitute.com — Scanbox Framework (report)