logo

Scouting a Threat Actor

ID: 9ad3b1a9-4419-5d56-bea5-d31c02a78b63

STIX ID: report--9ad3b1a9-4419-5d56-bea5-d31c02a78b63

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2025-04-28

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

Censys researchers uncovered a previously undocumented HTTP-based command-and-control toolkit dubbed "SCOUT PROJECT" (server, admin client, dropper builder, payload) exposed in a public archive; the actor used custom tooling to scan for and attempt exploitation of multiple recent critical vulnerabilities (ViteJS CVE-2025-30208, Langflow CVE-2025-3248, Next.js CVE-2025-29927), deployed a malicious dropper that communicates with the C2 over HTTP using fake PNG framing and RC4, and successfully exfiltrated data from at least one target while leaving identifiable IOCs and search fingerprints for hunting additional deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.