NKAbuse is a Go-based malware family that abuses the NKN (New Kind of Network) decentralized blockchain-backed peer-to-peer protocol for command-and-control and data exchange, making its traffic comparatively difficult to trace and filter with conventional security controls. It was initially documented as a multi-platform threat primarily targeting Linux systems, including Linux desktops and some IoT-class devices, with support observed for multiple CPU architectures such as MIPS, ARM, and 386. Later reporting identified previously undocumented variants used as backdoors or remote access trojans in active intrusion campaigns.
NKAbuse is associated with both botnet-style and backdoor functionality. Early reporting emphasized distributed denial-of-service capabilities, including HTTP, TCP, UDP, PING, ICMP, and SSL flooding. The malware also supports remote command execution, data exfiltration, and screenshot capture on compromised systems. More recent variants have been described as RAT-like backdoors capable of executing shell commands and returning output to the operator. The malware can maintain resilient communications through NKN and has been noted using external services to determine the victim host’s public IP address.
Observed delivery has included exploitation of internet-facing applications. One earlier case involved exploitation of Apache Struts vulnerability CVE-2017-5638 against a financial-sector target. In 2026, attackers were observed weaponizing CVE-2026-39987, a pre-authentication remote code execution flaw in Marimo Notebook, to deploy an NKAbuse variant staged via Hugging Face Spaces. That campaign combined malware deployment with credential theft and lateral movement into PostgreSQL and Redis, indicating NKAbuse can be part of broader post-exploitation activity rather than a standalone payload.
NKAbuse is notable as one of the first publicly reported malware families to operationalize NKN for C2, and later variants expanded beyond DDoS-oriented behavior into more general remote access and intrusion support roles. Its use of decentralized communications infrastructure, combined with Linux-focused targeting and flexible post-compromise capabilities, makes it relevant to both botnet and hands-on-keyboard intrusion scenarios.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-39987 was weaponized by attackers to deploy the NKAbuse blockchain botnet via HuggingFace, demonstrating that the model distribution ecosystem is a recognized and actively exploited attack surface.
A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. | One NKAbuse infection spotted by Kaspersky involves the exploitation of an old Apache Struts flaw (CVE-2017-5638) to attack a financial company.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Successful exploitation can result in: ... Persistence through cron jobs or startup scripts.
...the server accepts it with no credentials, allocates a PTY and a shell, and the attacker runs arbitrary commands as the Marimo process...
It directly launches a pseudo-terminal (PTY) session using pty.fork()... Once connected, attackers gain interactive shell access and can execute arbitrary commands on the host system.
CVE-2026-39987 is a critical pre-authentication remote code execution flaw in Marimo... A remote, unauthenticated attacker only has to complete a single WebSocket handshake to an exposed instance to obtain a full interactive shell as the user running the Marimo process.
Successful exploitation can result in: ... Persistence through cron jobs or startup scripts.
The payload (kagent) is a stripped Go ELF binary packed with UPX (4.3 MB → 15.5 MB).
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
...a blockchain-based (NKN) command-and-control channel that is hard to monitor or block.
The binary references NKN Client Protocol, WebRTC/ICE/STUN for NAT traversal, proxy management, and structured command handling.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A blockchain botnet mentioned as having been deployed via HuggingFace in a separate incident.
A backdoor variant deployed after exploitation of CVE-2026-39987. It is used for credential theft, lateral movement into PostgreSQL and Redis, and uses NKN blockchain-based command-and-control.
NKAbuse is being deployed after exploitation of the Marimo pre-auth RCE vulnerability, indicating it is used as a post-exploitation payload to compromise exposed systems.
A malware family originally described as DDoS-focused that abuses the NKN decentralized peer-to-peer network for communications. In the newly observed variant, it functions as a remote access trojan capable of executing shell commands on infected systems, returning output to the operator, and using WebRTC/ICE/STUN and proxy features for connectivity and NAT traversal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.