gs-netcat is a reverse shell and remote access utility from the Global Socket toolset that communicates via the Global Socket Relay Network (GSRN), allowing password-protected connectivity even when deployed on internal networks. In the provided reporting, it is used by multiple threat actors as a persistence and remote management mechanism rather than as a standalone malware family. Velvet Ant used a modified GS-Netcat reverse shell during Operation Highland on compromised internet-facing Linux servers, renaming the binary to "auditdb," hiding it in /usr/sbin/, disguising the process as "[khubd]," and persisting it via systemd unit files or SysVinit scripts. AryStinger, a botnet targeting outdated RTL819X-based routers and NAS devices, establishes persistent backdoors by downloading and deploying gs-netcat in its Standard variant, while the RTL819X variant uses Dropbear; the malware uses this channel for long-term remote access after exploiting vulnerabilities including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. ASEC also reported Larva-24010 distributing gs-netcat through a trojanized South Korean VPN installer, where PowerShell scripts installed gs-netcat alongside MeshAgent and NKNShell and established persistence through scheduled tasks. BI.ZONE separately reported attackers compromising public-facing web applications at Russian organizations and installing gs-netcat on servers for persistence before stealing database contents. High-confidence host artifacts directly mentioned in the content include the renamed binary "auditdb" in /usr/sbin/ and use of scheduled tasks, systemd, or SysVinit for persistence depending on the campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On exposed servers, the group deployed a modified GS-Netcat reverse shell. They renamed the binary “auditdb” and hid it in /usr/sbin/.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Retain access after reboot... Use any of the start-up scripts, such as /etc/rc.local ... Alternatively and if you do not have root privileges then just append the following line to the user's ~/.profile file.
For persistence, the malware abused systemd unit files on newer hosts and SysVinit scripts on older ones.
Retain access after reboot... Use any of the start-up scripts, such as /etc/rc.local ... Alternatively and if you do not have root privileges then just append the following line to the user's ~/.profile file.
AryStinger supports multiple task types, including internal/external network scanning, traffic tunnel forwarding/proxying... TUNNEL (Tunnel Penetration) Provides tunnel functionality, used to proxy or forward network traffic.
Uses the Global Socket Relay Network to connect TCP pipes... Once connected the library then negotiates a secure TLS connection(End-2-End).
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
gs-netcat is referenced as a tool used by AryStinger to maintain persistent remote access on compromised devices.
A modified reverse shell used on exposed servers for covert access and persistence, disguised with deceptive filenames and process names to evade detection.
gs-netcat is deployed by the AryStinger Standard variant to create a persistent remote management channel on infected NAS devices.
gs-netcat is a remote shell tool that leverages the Global Socket Relay Network for communication, allowing attackers to access infected systems even behind NAT or firewalls. It is installed for persistent remote access and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.