NetScan - Tool

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 8, 2025
Last Seen
June 16, 2026

NetScan is not mentioned in the provided article; therefore no specific characteristics or details about NetScan can be derived from this source.

Overview

NetScan is not mentioned in the provided article; therefore no specific characteristics or details about NetScan can be derived from this source. The article focuses on Makop ransomware campaigns that use GuLoader as a loader and employ privilege escalation to attack Indian businesses, illustrating typical attacker techniques in ransomware operations.

Related Threat Clusters

  • Exploitation of Bomgar RMM Vulnerability Triggers LockBit Ransomware Surge

    A critical remote code execution vulnerability (CVE-2026-1731) in Bomgar's remote monitoring and management (RMM) tool has led to a significant increase in cyberattacks, particularly involving LockBit ransomware. The…

    2 articles · Updated April 22, 2026
  • Trigona Ransomware Group Deploys Custom Exfiltration Tool for Data Theft

    In March 2026, the Trigona ransomware group, which operates as a Ransomware-as-a-Service (RaaS), utilized a newly developed custom tool named 'uploader_client.exe' to enhance their data exfiltration capabilities. This…

    9 articles · Updated April 24, 2026
  • DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications

    The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows…

    13 articles · Updated June 16, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1910 articles · Updated February 12, 2026
  • Makop Ransomware Enhancements Target Indian Organizations

    The Makop ransomware, a variant of the Phobos family, has been updated to include GuLoader malware for enhanced payload delivery. Recent attacks have primarily targeted Indian businesses, utilizing Remote Desktop…

    4 articles · Updated December 11, 2025

Recent Intelligence Reports

  • DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden — Security · June 16, 2026
  • Trigona Exfiltration Custom — www.security.com · April 24, 2026
  • Bomgar RMM Exploitation Fuels LockBit Attacks — Socprime · April 22, 2026
  • Iran-Linked Pay2Key Ransomware Group Re — Infosecurity-Magazine · March 26, 2026
  • Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses — Acronis · December 8, 2025

CVSS v3.1 Breakdown