scanbox

First seen
2014-06-01 00:00:00
Malware type
exploit-kit
Family
Malware family
Profile updated
2026-07-07 12:53:09

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:cn country_code:hk country_code:us

Context

ScanBox is a reconnaissance and exploitation framework used in watering hole attacks, often targeting media and government sectors. It collects information on targeted systems and users, typically seen in campaigns by China-based threat actors.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Scanbox_Framework_Not_Obfuscated (yara-rule)
  • SEKOIA_Apt_Scanbox_Obfuscated_Versions (yara-rule)

Reports & references

  • secureworks.com — Bronze Mohawk (report)
  • proofpoint.com — Chasing Currents Espionage South China Sea (report)
  • proofpoint.com — Ta413 Leverages New Friarfox Browser Extension Target Gmail Accounts Global (report)
  • volexity.com — Digital Crackdown Large Scale Surveillance And Exploitation Of Uyghurs (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Scanbox (report)
  • alienvault.com — Scanbox A Reconnaissance Framework Used On Watering Hole Attacks (report)
  • trustwave.com — Attacker Tracking Users Seeking Pakistani Passport (report)
  • nattothoughts.substack.com — Reconnaissance Scanning Tools Used (report)
  • resources.infosecinstitute.com — Scanbox Framework (report)

External references