Researchers reported that the Necro botnet—also tracked as N3Cr0m0rPh, FreakOut, and Necromorph—rapidly evolved from an older Python malware family into an active cross-platform campaign targeting both Linux and Windows systems. Multiple reports tied the operation to exploitation of public-facing flaws including CVE-2020-28188, CVE-2021-3007, and CVE-2020-7961, with later variants adding more n-day exploits such as those affecting TerraMaster, Genexis, Xinuos OpenServer, Zeroshell, and Visual Tools DVR VX16 4.2.28.0. The malware also spread through SSH and Telnet brute forcing, and researchers observed infection volumes ranging from hundreds of confirmed download attempts to estimates in the tens of thousands of compromised hosts.
The botnet used IRC-based command and control, later strengthened with DGA-generated domains, Tor, SSL-encrypted communications, polymorphic code, and PyInstaller-packed binaries to improve resilience and execution. Once installed, Necro enabled DDoS attacks, reverse shells, persistence, traffic sniffing, ARP poisoning, lateral movement, file infection, and JavaScript injection, while monetizing access primarily through XMRig-based Monero mining and, in some cases, Tezos mining. Cisco Talos also observed a Windows user-mode rootkit and a one-off apparent ransomware delivery attempt, underscoring that the operators were actively adding new payloads and exploit paths as the campaign matured.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
Juniper Threat Labs detected renewed Necro activity in the last week of September 2021, including a new exploit for Visual Tools DVR VX16 4.2.28.0 that installed both the bot and an XMRig-based Monero miner.
Juniper noted that a public proof of concept for the Visual Tools DVR VX16 exploit became available in July 2021.
Talos found that a later May 22 sample dropped embedded EternalBlue and EternalRomance from the main exploit path and instead used credential-based remote service creation over port 445.
Talos reported that a May 18 Necro variant embedded Python implementations of EternalBlue and EternalRomance for SMB-based propagation on Windows.
Cisco Talos observed limited Tezos mining tied to wallet tz1NfDViBuZwi31WHwmJ4PtSsVtNX2yLnhG7 in some honeypot samples starting on May 9, 2021.
Juniper stated that Necro had previously expanded its exploit arsenal again in May 2021.
Cisco Talos observed notable growth in Necro activity during May 2021 and analyzed newer variants that added multiple exploits, Windows rootkit functionality, and cryptocurrency mining features.
A March 2021 360Netlab report documented another Necro upgrade, describing Tor use, dynamic-domain DGA, and targeting of both Windows and Linux systems.
Juniper said Necro had previously expanded its exploit arsenal in March 2021, marking another development stage in the botnet's propagation capabilities.
360Netlab published analysis of Necro's newer Linux-focused variants, highlighting DGA-generated C2 domains, stronger obfuscation, PyInstaller ELF payloads, and XMRig delivery.
360Netlab reported that on January 20, 2021, Necro version 3 changed its DGA seeds from 3 to 4096 and began encrypting communications with SSL.
Check Point Research reported an active FreakOut botnet campaign exploiting CVE-2020-28188, CVE-2021-3007, and CVE-2020-7961 to deploy an IRC-controlled Python bot and, in later variants, XMRig miners.
Check Point observed the first attempt to download the out.py payload from gxbrowser[.]net as attackers exploited TerraMaster, Zend Framework, and Liferay servers.
360Netlab said CVE-2021-3007 was publicly revealed on January 4, 2021, shortly before Necro incorporated the vulnerability into its propagation arsenal.
Juniper Threat Labs stated that Necro was first discovered in January 2021.
Check Point found an earlier malware variant containing comments and a calling card that referenced an update on January 1, 2021.
360Netlab observed continuous new Necro variants from January 1, 2021 onward, including three Linux-targeting 2021 versions linked to the same operators.
Check Point reported the botnet's IRC server had been running since late November 2020, with about 300 users and five channels at the time of observation.
Researchers described Necro/N3Cr0m0rPh as a Python-based botnet family first discovered in 2015, with early samples targeting Windows systems.
360Netlab reported Necro exploiting CVE-2020-35665 eight days before the vulnerability was publicly disclosed on December 23, 2020, showing rapid operational use of the flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
blogs.juniper.net
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourceblog.netlab.360.com
Open sourceblog.netlab.360.com
Open sourceblog.netlab.360.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.