net is a Linux botnet malware family with application-layer and game-server distributed denial-of-service capabilities. An analyzed x86-64 variant is stripped and statically linked with glibc. Its attack modules include protocol-specific functionality for FiveM, Garry's Mod, CS:GO, TeamSpeak 3, Source Engine, Quake-derived services, and Discord. It supports HTTP-header synthesis, rotating browser User-Agent strings, and cookie replay intended to circumvent anti-bot controls, although successful Cloudflare bypass has not been established.
The malware uses primary and alternate command-and-control connection paths and XOR-encoded configuration. Its SOCKS5 functionality is an outbound client with an additional cryptographic layer, rather than a proxy server. Defense-evasion and host-control features include terminating competing malware, suppressing watchdogs, and masquerading as a kernel thread. It contains persistence support for recovery scripts, SysV init, cron, and systemd services.
Distribution uses a shell dropper that retrieves architecture-specific payloads with wget or curl, executes them, and removes deployment artifacts. A confirmed operator attribution has not been established. net is distinct from the legitimate Windows Net administrative utility; Windows account, group, service, and network-share operations associated with that utility are not capabilities of this malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The net start and net stop commands can be used in Net to execute or stop Windows services.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
/etc/init.d/.sys_daemon ... update-rc.d sys_daemon defaults ... chkconfig --add sys_daemon.
/etc/cron.d/.sys_update ... /etc/cron.d/netupd ... @reboot root /bin/sh /var/tmp/.sys_recovery.sh &.
Net ... Account Manipulation: Additional Local or Domain Groups
APT3 has been known to create or enable accounts, such as support_388945a0 . ... APT5 has created Local Administrator accounts to maintain access ... DarkGate creates a local user account, SafeMode, via net user commands.
Adversaries may create a local account to maintain access to victim systems. ... Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
/etc/init.d/.sys_daemon ... update-rc.d sys_daemon defaults ... chkconfig --add sys_daemon.
/etc/cron.d/.sys_update ... /etc/cron.d/netupd ... @reboot root /bin/sh /var/tmp/.sys_recovery.sh &.
XOR 0x22 / 0x09 / 0x5A string tables ... constructs the C2 in registers so the address never appears as a string.
Plaintext name pool used with prctl(PR_SET_NAME) / set_process_name: [kswapd0], [kthreadd], ... [watchdog/0].
Cobalt Strike ... System Service Discovery; ... Net ... System Service Discovery
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
Sample 1 embeds 150 IPv4 /24 CIDR blocks — an operator-configured scanner scope.
Cobalt Strike ... System Network Connections Discovery; ... Net ... System Network Connections Discovery; ... netstat ... System Network Connections Discovery
Cobalt Strike ... Permission Groups Discovery: Local Groups; ... Net ... Permission Groups Discovery: Local Groups
Brute Ratel C4 can use LDAP queries, net group "Domain Admins" /domain and net user /domain for discovery. OilRig has run net group "domain admins" /domain and net group "Exchange Trusted Subsystem" /domain to get account listings on a victim. Wizard Spider has identified domain admins through the use of net group "Domain admins" /DOMAIN.
/proc/cpuinfo → processor (CPU count for attack-thread scaling), BOGOMIPS.
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
The IRC strings ... indicate a second, IRC-based control path.
Application Layer Protocol: Web T1071.001 — HTTP L7 floods, Cloudflare bypass, C2 on port 80.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Built-in Windows utility abused to find shared drives and directories on remote and local systems.
A built-in Windows utility whose domain-related commands can gather and manipulate domain account information.
A native Windows utility whose commands such as net view are used to gather information about remote systems.
Windows built-in utility (net.exe) used to enumerate shares (net view/net share).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.