How a Contractor's Scanning Platform Turns a Botnet Into a Target List
State-aligned intrusion crews now run like factory lines: a botnet finds hosts, a scanner fingerprints them, and old, reliable exploits do the rest.
When the FBI and CISA published advisory AA26-281A in October 2026 and the Justice Department seized the domains behind a scanner called MicroScan, they documented something most defenders underestimate: the economics of a state-aligned intrusion operation now resemble a factory line. The Chinese contractor named in the advisory, Integrity Technology Group, did not need an expensive zero-dayZero-Day🛡️A security vulnerability that is exploited or publicly disclosed before the software vendor can release a patch, giving developers 'zero days' to fix it. to compromise a power company, airports and universities. It needed a way to find, at internet scale, the handful of hosts still running a bug that was patched in 2015. This article explains how that pipeline works and why it keeps paying off.
The three stages of an industrial scanning operation
A mass-exploitation pipeline separates three jobs that a single penetration tester would do by hand: finding hosts, identifying what runs on them, and exploiting the ones that match. Keeping them separate is what lets the operation scale.
The first stage is discovery. The operators in AA26-281A ran it on a botnetBotnet🛡️A network of internet-connected devices compromised and controlled by an operator, used for denial-of-service attacks, proxying malicious traffic, credential stuffing or spam. Edge routers are prized botnet hosts because they are numerous, always on, directly reachable and rarely inspected by their owners. of consumer devices infected with a Mirai variant, the same kind of infrastructure the FBI dismantled as Raptor Train in 2024. Using thousands of compromised home routers and cameras as the source means the scanning traffic comes from everywhere at once, so no single IP addressIP Address🔐A unique numerical identifier assigned to every device connected to the internet. stands out and no firewallFirewall🌐Security system that monitors and controls network traffic based on predetermined rules. blocklist covers it. The sweep is deliberately narrow: six ports, 21, 22, 53, 80, 443 and 1080. That list is not an accident. Each one maps to a service the operators already know how to exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access..
The second stage is fingerprinting. Hosts that answered the sweep are handed to a dedicated scanner, in this case a Python application holding more than 1,300 exploitation scripts. Its job is to turn "something is listening on port 80" into "this is ONLYOFFICE Document Server 5.4, which is vulnerable to CVE-2021-3199." The scanner does not need to be clever. It needs to be comprehensive and fast, and it needs an up-to-date library of checks.
The third stage is exploitation, and by the time a host reaches it the hard thinking is done. The target is known, the version is known, and a working exploit is already written. A human operator, or an automated step, fires the single request that the matching CVE requires.
Why old vulnerabilities are the preferred ammunition
It is tempting to read a list of 2015 and 2016 CVEs as a sign of an unsophisticated adversary. The opposite is closer to the truth. Old, reliable, widely-documented bugs are the rational choice for a pipeline built on scale.
A zero-day is expensive, perishable and loud. It costs money or research time to acquire, it stops working the moment it is discovered and patched, and using it against low-value targets risks burning it. An n-day vulnerabilityN-Day Vulnerability🛡️A publicly disclosed vulnerability with a patch available, exploited in the window before defenders apply the fix — the vendor has known about it for N days, in contrast to a zero-day. Most real-world compromise comes from n-days, because patches and advisories double as attacker roadmaps. that has had a patch for a decade has none of those problems. The exploit is public, often with a Metasploit or Exploit-DB module. It will never be "caught" and retired, because it is already known. And crucially, the population of vulnerable hosts never reaches zero. There is always another forgotten appliance, another server a vendor shipped with an embedded copy of the component, another system whose owner believes "we patched that years ago" without ever confirming it.
The CVEs in the advisory were chosen for exactly these properties. CVE-2015-3306 in ProFTPD is a single pair of FTP commands that read and write any file. CVE-2016-3081 in Apache Struts executes code through a crafted request parameter. CVE-2021-3199 in ONLYOFFICE is a directory-traversal upload. Each is a one-request compromise with no authentication, which is precisely what a scanning pipeline can automate. This is the same n-day dynamic that makes a vendor's severity rating only the beginning of the story, a theme explored in Why 'We Patched That in 2015' Is Not an Answer to a KEV Deadline.
The two CVEs that break the pattern
Two of the eight exploited CVEs do not fit the one-request-to-code-execution mould, and understanding why clarifies what the pipeline is actually optimised for.
CVE-2015-5477 in ISC BIND only crashes the DNS daemon. It yields no access and no data. It appears on the list because port 53 is already in the scan set and a DNS outage is a useful disruption during a larger operation, not because it is an entry point. CVE-2023-22894 in Strapi is the reverse case: it is powerful, exposing password hashes and reset tokens, but it requires admin-panel access first. That makes it a second-stage tool, used after credentials are reused or a session is stolen, rather than a way in. Recognising which vulnerabilities are doors and which are rooms you can only loot once inside is central to triage.
What this means for how you defend
The defensive implication of an industrial pipeline is that you cannot win by patching faster than the adversary writes exploits, because the adversary is not writing exploits. It is finding hosts. The leverage is therefore on the discovery stage, not the exploit stage.
That means the single most valuable control is knowing what you expose before the botnet maps it for you. An accurate, continuously-updated external inventory of every service answering on those six ports is worth more than any individual patch, because it tells you where your forgotten ProFTPD and Struts instances actually are. How to Find Which of Your Admin Consoles Are Reachable From the Internet walks through building that view. The second control is detecting the activity that follows a successful exploit, since a pipeline this noisy leaves clear traces once it moves to hands-on-keyboard work; How to Spot DCSyncDCSync🛡️A credential-theft technique in which an attacker impersonates a domain controller and asks a real one to replicate account data, including password hashes, over the normal Active Directory replication protocol. and Mailbox Harvesting After a Web Server Is Breached covers that side. The pipeline's strength is its scale. Its weakness is that it can only exploit what you have left exposed and forgotten.