Necro is a Python-based botnet, also known as Necromorph, N3Cr0m0rPh, and FreakOut, that targets Windows and Linux systems. First identified in 2015, it is associated with the Keksec threat group. Its principal activities include distributed denial-of-service attacks, cryptocurrency mining, malware deployment, and traffic interception. It is distinct from the Android Trojan dropper also called Necro.
Necro propagates through network scanning, SSH and Telnet weak-password attacks, exploitation of vulnerable internet-facing applications, and SMB-based propagation. Exploited products include TerraMaster TOS, Zend Framework, Laravel, Oracle WebLogic, Liferay Portal, and VMware vCenter Server. Some Windows variants incorporate EternalBlue and EternalRomance exploits, while others use credential-based remote service creation. Payloads are distributed as Python scripts with standalone interpreters or as PyInstaller-packaged Windows and Linux executables.
Operators control Necro through IRC-based command-and-control communications. Variants use Tor proxies, domain generation algorithms, encrypted communications, and polymorphic Python code to resist detection and infrastructure blocking. Necro supports reverse shells, file download and execution, configurable scanning, packet sniffing, ARP spoofing, and multiple DDoS methods, including UDP, SYN, HTTP, Slowloris, and amplification attacks. It establishes startup persistence on both supported operating systems. Windows variants inject the r77 user-mode rootkit into other processes to conceal malicious activity.
Necro deploys XMRig miners and can install additional botnet payloads such as Gafgyt_tor. On compromised Linux web servers, it modifies web files to inject malicious JavaScript into pages served to visitors. Associated browser payloads support cryptocurrency mining, keylogging, form-data collection, cookie and clipboard theft, arbitrary JavaScript execution, and browser-based DDoS attacks. Its traffic-sniffing functionality also forwards captured network data to attacker infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Necro scans for and propagates through Laravel RCE (CVE-2021-3129); its exploit establishes a reverse shell that downloads a Bash script, Necro, Gafgyt_tor, and a mining program. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro resumed spreading using the previous Zend RCE (CVE-2021-3007) alongside other vulnerabilities. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro exploits WebLogic RCE (CVE-2020-14882) with separate Linux and Windows exploit chains that download and execute Necro and mining payloads. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro resumed spreading using the previous TerraMaster RCE (CVE-2020-35665) alongside other vulnerabilities. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
The three more popular exploits integrated by Necro can be seen in Figures 9–11... 1. TerraMaster RCE: CVE-2020-28188 | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
2021.3.20 CVE-2021-21972 2021.2.27 VMware_vCenterServer Necro | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
2021.1.8 CVE-2020-7961 2020.7 Liferay Portal Necro | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
The version released on May 18 also included Python versions of EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0147) exploits with a Windows download command line as the payload. | A newly discovered malware campaign utilizing the Necro Python bot shows this actor is adding new functionality and improving its chances of infecting vulnerable systems.
The version released on May 18 also included Python versions of EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0147) exploits with a Windows download command line as the payload. | A newly discovered malware campaign utilizing the Necro Python bot shows this actor is adding new functionality and improving its chances of infecting vulnerable systems.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2021 – Spytech Necro is an updated version of Necro python malware with significant updates to the C2 protocol and additional exploits.
Further analysis revealed that the family is closely related to the Necro family we made public in January, and is behind the same group of people, the so-called keksec group.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
The Windows exploit uses Powershell, which first downloads the packaged Python 2.7 executable (py.exe), then downloads and executes Necro (setup.py).
Necro downloads x86.dll or x64.dll, corresponding to the open-source r77-rootkit project, which hides files, directories, processes, registry items, connections, and other entities.
Necro implemented a code morphing algorithm based on the abstract syntax tree (AST), achieving randomized object names and broader obfuscation; samples had a reported VT detection rate of 0.
A very traditional technique on Linux systems is to use random strings to override argv parameters and prctl(PR_SET_NAME,buf) to change the process name and start parameters in order to disguise the process.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
Apart from installing miner code, the JavaScript-based bot contains additional functionality to accept commands from the C2 server and it may be used to steal data from the clipboard, by logging keystrokes and launching DoS attacks.
The malicious JavaScript monitors events and reports data through /l.php to upload keyboard records.
The scanners used by Keksec are mainly telnet and SSH weak password scan and exploit scan.
After receiving the scan command, the built-in weak password brute force starts... SSH weak passwords are constantly updated by version upgrades, and new weak passwords are added to replace some of the less effective ones.
Apart from installing miner code, the JavaScript-based bot contains additional functionality to accept commands from the C2 server and it may be used to steal data from the clipboard, by logging keystrokes and launching DoS attacks.
The malicious JavaScript monitors events and reports data through /l.php to upload keyboard records.
Keksec’s malware mainly uses Gafgyt and IRC protocols to send commands.
The IRC protocol is the most widely used protocol in Keksec, and is supported by the Tsunami, Necro and DarkIRC families.
We found Tor proxy being used to communicate with the C2 in both Gafgyt and Necro.
Necro supports Tor for C2; its code includes multiple Tor proxy IP addresses and an onion-service C2 address.
Downloaded bash scripts download and execute another script malware.sh, Gafgyt_tor, and a mining program; Windows PowerShell downloads py.exe and setup.py.
Necro tampers with web service pages to perform browser mining; the injected page loads a mining JavaScript script from cloud-miner.de.
Necro integrates a Tor proxy-based DDoS attack method, torflood; other JavaScript commands issue repeated POST requests, image loads, and iframe loads to DDoS targets.
192 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Only mentioned as a related headline; no functional details provided in the analyzed content.
Only mentioned as a related headline; no functional details provided in the analyzed content.
Android dropper distributed via trojanized apps/mods (including on Google Play) that uses obfuscation and steganography to conceal payloads; monetizes via invisible ad interactions and paid subscription fraud; can download additional malware.
KekSec-developed botnet mentioned as background context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.