Alpha Cyber

Inside Scranos Mapping a Cross-Platform, Rootkit-Enabled Spyware Operation

In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Scranos Rootkit Graph

In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection. One such example is the Scranos spyware campaign, a multi-platform, rootkit-backed spyware operation that demonstrates how threat actors build and manage entire ecosystems to conduct sustained attacks.

Our security analysts have dissected Scranos’s infrastructure and mapped the relationships between its payload delivery mechanisms, command-and-control (C2) servers, monetization modules, and domain infrastructure. This post presents a snapshot of that infrastructure along with a list of active IOCs (Indicators of Compromise) to block immediately.

Scranos: A Deeper Look at the Spyware Infrastructure

Scranos is not just a piece of malware, it’s an operation. Here’s how it works:

1. Initial Infection & Payload Delivery

Victims are typically infected through trojanized software installers that appear to be cracked or free versions of legitimate applications. Once launched, the installer delivers a signed rootkit that ensures the spyware remains persistent and hidden from antivirus detection.

2. Data Harvesting & Surveillance

Upon successful installation, Scranos begins silently harvesting:

Browser credentials
Auto-fill form data
Payment information
Browsing history and cookies

It also disables certain Windows protections and intercepts communications through proxy injection.

3. Cross-Platform Components

Android users are targeted through rogue apps that request excessive permissions. These apps are capable of:

Reading SMS and app data
Capturing login information
Sending harvested data to command-and-control servers

4. Monetization & Affiliate Abuse

Scranos doesn’t stop at espionage. It monetizes infections by:

Injecting ads into browsers
Forcing redirections to affiliate marketing sites
Subscribing users to paid services without consent
Generating fraudulent YouTube traffic for profit

5. Resilient, Multi-Layered Infrastructure

Scranos employs a modular, evasive infrastructure that includes:

Rotating domain names and disposable servers
Fast-flux DNS tactics to evade blocking
Redundant download servers for malware delivery
Hardcoded C2 fallback options

By mapping this infrastructure, we uncovered a web of command channels and supporting domains that actively enable Scranos to operate under the radar.

Scranos IOCs to Block Immediately

We strongly recommend blocking the following IOCs at the firewall, DNS, email gateway, and endpoint protection levels.

TypeValueFirst Seen
FileHash (MD5)d43ac96995c02e4a7ccece3059730b95Sep 13, 2023, 04:53 AM
Domainapi168168.comSep 13, 2023
Domaincreatenews.topSep 13, 2023
Domainfastdataxew.infoSep 13, 2023
Domainfiledistrserver.pwSep 13, 2023
Domaininstall-apps.comSep 13, 2023
Domaininstall-pixel.comSep 13, 2023
Domainjnjeadsdf.comSep 13, 2023
Domainlfoweiro129301.pwSep 13, 2023
Hostnameapi.dmnaxn3.comSep 13, 2023

Why Infrastructure Mapping Matters

Traditional malware detection isn’t enough. Modern threats like Scranos leverage entire infrastructures, from domain registrations to CDN-backed delivery, to remain agile and evasive.

By mapping these infrastructures, we can:

Predict lateral movement within and across networks
Identify secondary payload sources and C2 redundancies
Preemptively block related infrastructure before reuse
Enable smarter, faster detection rules

Take Action Before Scranos Hits Your Network

If Scranos proves anything, it’s that attackers are becoming architects. They build digital infrastructures that are scalable, automated, and designed for long-term exploitation.

Our team can help you map threats before they hit. Contact us today to learn how our infrastructure mapping and IOC response services can protect your organization from advanced, persistent threats like Scranos.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]