Inside Scranos Mapping a Cross-Platform, Rootkit-Enabled Spyware Operation
In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection.

In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection. One such example is the Scranos spyware campaign, a multi-platform, rootkit-backed spyware operation that demonstrates how threat actors build and manage entire ecosystems to conduct sustained attacks.
Our security analysts have dissected Scranos’s infrastructure and mapped the relationships between its payload delivery mechanisms, command-and-control (C2) servers, monetization modules, and domain infrastructure. This post presents a snapshot of that infrastructure along with a list of active IOCs (Indicators of Compromise) to block immediately.
Scranos: A Deeper Look at the Spyware Infrastructure
Scranos is not just a piece of malware, it’s an operation. Here’s how it works:
1. Initial Infection & Payload Delivery
Victims are typically infected through trojanized software installers that appear to be cracked or free versions of legitimate applications. Once launched, the installer delivers a signed rootkit that ensures the spyware remains persistent and hidden from antivirus detection.
2. Data Harvesting & Surveillance
Upon successful installation, Scranos begins silently harvesting:
Browser credentials
Auto-fill form data
Payment information
Browsing history and cookies
It also disables certain Windows protections and intercepts communications through proxy injection.
3. Cross-Platform Components
Android users are targeted through rogue apps that request excessive permissions. These apps are capable of:
Reading SMS and app data
Capturing login information
Sending harvested data to command-and-control servers
4. Monetization & Affiliate Abuse
Scranos doesn’t stop at espionage. It monetizes infections by:
Injecting ads into browsers
Forcing redirections to affiliate marketing sites
Subscribing users to paid services without consent
Generating fraudulent YouTube traffic for profit
5. Resilient, Multi-Layered Infrastructure
Scranos employs a modular, evasive infrastructure that includes:
Rotating domain names and disposable servers
Fast-flux DNS tactics to evade blocking
Redundant download servers for malware delivery
Hardcoded C2 fallback options
By mapping this infrastructure, we uncovered a web of command channels and supporting domains that actively enable Scranos to operate under the radar.
Scranos IOCs to Block Immediately
We strongly recommend blocking the following IOCs at the firewall, DNS, email gateway, and endpoint protection levels.
| Type | Value | First Seen |
|---|---|---|
| FileHash (MD5) | d43ac96995c02e4a7ccece3059730b95 | Sep 13, 2023, 04:53 AM |
| Domain | api168168.com | Sep 13, 2023 |
| Domain | createnews.top | Sep 13, 2023 |
| Domain | fastdataxew.info | Sep 13, 2023 |
| Domain | filedistrserver.pw | Sep 13, 2023 |
| Domain | install-apps.com | Sep 13, 2023 |
| Domain | install-pixel.com | Sep 13, 2023 |
| Domain | jnjeadsdf.com | Sep 13, 2023 |
| Domain | lfoweiro129301.pw | Sep 13, 2023 |
| Hostname | api.dmnaxn3.com | Sep 13, 2023 |
Why Infrastructure Mapping Matters
Traditional malware detection isn’t enough. Modern threats like Scranos leverage entire infrastructures, from domain registrations to CDN-backed delivery, to remain agile and evasive.
By mapping these infrastructures, we can:
Predict lateral movement within and across networks
Identify secondary payload sources and C2 redundancies
Preemptively block related infrastructure before reuse
Enable smarter, faster detection rules
Take Action Before Scranos Hits Your Network
If Scranos proves anything, it’s that attackers are becoming architects. They build digital infrastructures that are scalable, automated, and designed for long-term exploitation.
Our team can help you map threats before they hit. Contact us today to learn how our infrastructure mapping and IOC response services can protect your organization from advanced, persistent threats like Scranos.



