Netcat is a legitimate, dual-use command-line networking utility for reading and writing data over network connections. Attackers commonly abuse it to establish reverse shells and command-and-control channels, providing interactive command execution on compromised systems. It is not inherently a malware family, and its use does not by itself imply malicious activity.
Malicious deployments include Windows and Linux servers, internet-connected cameras, and enterprise network appliances. Netcat has been downloaded and executed after exploitation of Apache ActiveMQ, WebLogic, HTTP File Server, and other exposed applications. A compromised GoAhead camera contained a Netcat reverse-shell command following exploitation of CVE-2017-8225. UAT-11823 deployed a Netcat reverse shell during attacks against Cisco Secure Firewall Management Center. Attackers have also installed Netcat on a Korean medical institution’s Windows IIS server.
Netcat access supports post-compromise control and further tool deployment; an observed Apache ActiveMQ attack used that access to install AnyDesk. Associated users include z0Miner, APT32, and Ember Bear. APT32 disguised a Netcat binary as a Windows update, while other attackers renamed it to resemble legitimate Windows components. Netcat-based reverse-shell functionality has also appeared in a cryptomining campaign distributed through trojanized tools advertised on GitHub and YouTube. Cryptocurrency mining, credential theft, and persistence performed by accompanying payloads are distinct from Netcat’s networking and shell-access role.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This threat actor downloaded Netcat as userinit.exe and executed it.
The earlier GeoServer attack installed a coin miner and NetCat. The conclusion states that attackers could subsequently use the installed NetCat to install additional malware or steal information.
RAT 악성코드들과 CobaltStrike, Netcat 등이 사용되고 있다.
"...an unauthorized party used a previously unknown, zero-day remote code execution (RCE) vulnerability to access certain GoAnywhere customers’ systems. This vulnerability was assigned CVE-2023-0669."
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor downloaded Netcat as userinit.exe and executed it.
UAT-11823 deployed a Netcat reverse shell through a malicious license.tmp file executed by package_info.pl.
...Netcat... may have been used by the attackers as well.
Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST).
19 distinct techniques documented for this family, organized by ATT&CK tactic.
“We built a container image with netcat installed, deployed it as an AgentCore Runtime, and connected back with a reverse shell.”
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Its simplicity masks a surprising versatility: it can copy files, tunnel traffic, relay ports, scan networks, and sometimes even replace more complex post-exploitation tools.
UAT-11823 modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure.
Finally, the stage 4 payload executes the reverse shell script located at /data/data/com.termux/_rev.sh , establishing a root reverse shell connection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-line networking tool used in this activity to establish a reverse shell.
NetCat is a legitimate network utility often abused by attackers as a backdoor or for lateral movement, file transfer, and remote command execution.
A legitimate networking utility explicitly described here as an attacker-installed tool supporting further malicious activity. The article identifies potential follow-on malware installation and information theft, but does not establish that those subsequent actions occurred.
A legitimate networking utility frequently abused by attackers to create bind/reverse shells and facilitate remote command execution after initial exploitation (here, via ShellShock).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.