Necro, also known as Necromorph and FreakOut, is a Python-based cross-platform botnet family first identified in 2015 and associated with the Keksec threat actor. Early variants targeted Windows, while later actively maintained variants targeted Linux servers, IoT devices, and vulnerable internet-facing applications. Necro propagates through exploitation of public-facing vulnerabilities, Telnet and SSH weak-password attacks, and SMB-based propagation. Observed exploitation includes vulnerabilities in Laravel, Oracle WebLogic, TerraMaster, Zend Framework, Liferay Portal, VMware vCenter, and other server, appliance, and IoT products.
Necro uses IRC-based command-and-control and later incorporated Tor-routed communications, DGA-generated command-and-control infrastructure, encrypted communications, and polymorphic Python abstract-syntax-tree obfuscation. It supports scanning, credential brute forcing, distributed denial-of-service attacks, reverse-shell access, payload download and execution, packet sniffing, and ARP spoofing. Linux infections have deployed cryptomining payloads and modified web content to inject malicious JavaScript into visitor browsers. That JavaScript component has supported browser cryptomining, keylogging, form and clipboard collection, cookie theft, browser-based denial-of-service activity, and execution of operator-supplied JavaScript.
Windows variants establish persistence and deploy the r77 user-mode rootkit through process injection to conceal malicious files, processes, and registry artifacts. Necro has primarily been monetized through cryptomining and denial-of-service activity, with reported information-theft and additional-payload delivery capabilities. The name Necro has also been used for an Android multi-component Trojan/dropper observed in trojanized applications; no relationship between that Android malware and the Keksec-associated Python botnet is established here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Necro scans for and propagates through Laravel RCE (CVE-2021-3129); its exploit establishes a reverse shell that downloads a Bash script, Necro, Gafgyt_tor, and a mining program. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro resumed spreading using the previous Zend RCE (CVE-2021-3007) alongside other vulnerabilities. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro exploits WebLogic RCE (CVE-2020-14882) with separate Linux and Windows exploit chains that download and execute Necro and mining payloads. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Necro resumed spreading using the previous TerraMaster RCE (CVE-2020-35665) alongside other vulnerabilities. | A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
The three more popular exploits integrated by Necro can be seen in Figures 9–11... 1. TerraMaster RCE: CVE-2020-28188 | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
2021.3.20 CVE-2021-21972 2021.2.27 VMware_vCenterServer Necro | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
2021.1.8 CVE-2020-7961 2020.7 Liferay Portal Necro | The year-long attack campaign can be divided into two phases; high-frequency attacks are maintained until December 2020, and resumed in January 2021, when Keksec starts spreading the brand new malware family Necro.
The version released on May 18 also included Python versions of EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0147) exploits with a Windows download command line as the payload. | A newly discovered malware campaign utilizing the Necro Python bot shows this actor is adding new functionality and improving its chances of infecting vulnerable systems.
The version released on May 18 also included Python versions of EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0147) exploits with a Windows download command line as the payload. | A newly discovered malware campaign utilizing the Necro Python bot shows this actor is adding new functionality and improving its chances of infecting vulnerable systems.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new variant of Necro resumed spreading after a month of silence, adding Windows targeting, rootkit-based concealment, Tor C2 and Tor-based DDoS, subdomain-DGA C2 generation, and web-page JavaScript injection.
Further analysis revealed that the family is closely related to the Necro family we made public in January, and is behind the same group of people, the so-called keksec group.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
The Windows exploit uses Powershell, which first downloads the packaged Python 2.7 executable (py.exe), then downloads and executes Necro (setup.py).
Necro downloads x86.dll or x64.dll, corresponding to the open-source r77-rootkit project, which hides files, directories, processes, registry items, connections, and other entities.
Necro implemented a code morphing algorithm based on the abstract syntax tree (AST), achieving randomized object names and broader obfuscation; samples had a reported VT detection rate of 0.
A very traditional technique on Linux systems is to use random strings to override argv parameters and prctl(PR_SET_NAME,buf) to change the process name and start parameters in order to disguise the process.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
Apart from installing miner code, the JavaScript-based bot contains additional functionality to accept commands from the C2 server and it may be used to steal data from the clipboard, by logging keystrokes and launching DoS attacks.
The malicious JavaScript monitors events and reports data through /l.php to upload keyboard records.
The scanners used by Keksec are mainly telnet and SSH weak password scan and exploit scan.
After receiving the scan command, the built-in weak password brute force starts... SSH weak passwords are constantly updated by version upgrades, and new weak passwords are added to replace some of the less effective ones.
Apart from installing miner code, the JavaScript-based bot contains additional functionality to accept commands from the C2 server and it may be used to steal data from the clipboard, by logging keystrokes and launching DoS attacks.
The malicious JavaScript monitors events and reports data through /l.php to upload keyboard records.
Keksec’s malware mainly uses Gafgyt and IRC protocols to send commands.
The IRC protocol is the most widely used protocol in Keksec, and is supported by the Tsunami, Necro and DarkIRC families.
We found Tor proxy being used to communicate with the C2 in both Gafgyt and Necro.
Necro supports Tor for C2; its code includes multiple Tor proxy IP addresses and an onion-service C2 address.
Downloaded bash scripts download and execute another script malware.sh, Gafgyt_tor, and a mining program; Windows PowerShell downloads py.exe and setup.py.
Necro tampers with web service pages to perform browser mining; the injected page loads a mining JavaScript script from cloud-miner.de.
Necro integrates a Tor proxy-based DDoS attack method, torflood; other JavaScript commands issue repeated POST requests, image loads, and iframe loads to DDoS targets.
192 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Only mentioned as a related headline; no functional details provided in the analyzed content.
Only mentioned as a related headline; no functional details provided in the analyzed content.
Android dropper distributed via trojanized apps/mods (including on Google Play) that uses obfuscation and steganography to conceal payloads; monetizes via invisible ad interactions and paid subscription fraud; can download additional malware.
KekSec-developed botnet mentioned as background context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.