FreakOut, also known as Necro and N3Cr0m0rPh, is a Python-based IRC-controlled botnet malware family and campaign active against internet-exposed systems. It has been observed targeting Linux servers and devices, and some reporting also describes multi-platform targeting that includes Windows. The malware is heavily obfuscated, uses polymorphic techniques to alter its code between deliveries, and has employed user-mode rootkit functionality to hide dropped malicious components on compromised hosts.
FreakOut is primarily associated with opportunistic mass exploitation and botnet expansion. Early activity leveraged public-facing vulnerabilities in products including TerraMaster TOS, Zend Framework or Laminas-based applications, and Liferay Portal. Later variants expanded propagation to additional enterprise and edge-facing software and services, including VMware vCenter, Vesta Control Panel, ZeroShell, SCO OpenServer, Genexis devices, OTRS, and SMB services via EternalBlue and EternalRomance, while also using weak-credential brute forcing over SSH and Telnet. The malware scans for targets, attempts exploitation with built-in modules, and can spread laterally or externally by generating target ranges and compromising additional hosts.
Once installed, FreakOut enrolls victims into an IRC botnet and exposes a broad post-compromise feature set. Documented capabilities include multiple distributed denial-of-service methods such as UDP, SYN, HTTP, DNS flooding, and Slowloris-style attacks; reverse-shell or backdoor access; process termination; persistence through startup modification; traffic sniffing via ARP spoofing; and exfiltration of intercepted network data. The malware has also been observed downloading and deploying XMRig to mine Monero, making cryptomining a secondary monetization path alongside botnet operations.
Infrastructure and code-history analysis has linked FreakOut to the actor name “Freak” and related aliases including Fl0urite and Keksec, with continuity to the older Necro/N3Cr0m0rPh botnet lineage first seen in 2015. Newer 2021 variants introduced stronger obfuscation, self-repacking behavior, domain-generation techniques, encrypted communications, and delivery of both Python scripts and packaged ELF binaries to improve execution on systems lacking the expected interpreter. Overall, FreakOut is best characterized as a modular Python botnet malware family focused on rapid propagation, DDoS operations, network abuse, and opportunistic cryptomining across exposed server environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malware, dubbed FreakOut by CheckPoint researchers in January (aka Necro and N3Cr0m0rPh), is an obfuscated Python script designed to evade detection using a polymorphic engine and a user-mode rootkit that hides malicious files dropped on compromised systems.
The malware, dubbed FreakOut by CheckPoint researchers in January (aka Necro and N3Cr0m0rPh), is an obfuscated Python script designed to evade detection using a polymorphic engine and a user-mode rootkit that hides malicious files dropped on compromised systems.
The malware, dubbed FreakOut by CheckPoint researchers in January (aka Necro and N3Cr0m0rPh), is an obfuscated Python script designed to evade detection using a polymorphic engine and a user-mode rootkit that hides malicious files dropped on compromised systems.
CVE-2021-3007 This vulnerability is caused by the unsecured deserialization of an object. In versions higher than Zend Framework 3.0.0, the attacker abuses the Zend3 feature that loads classes from objects in order to upload and execute malicious code in the server. | FreakOut is an attack campaign that utilizes three vulnerabilities, including some newly released, to compromise different servers. The threat actor behind the attack, named “Freak”, managed to infect many devices in a short period of time, and incorporated them into a botnet, which in turn is used for DDoS attacks and crypto-mining.
The campaign exploits these recent vulnerabilities: CVE-2020-28188, CVE-2021-3007 and CVE-2020-7961. These allow the attacker to upload and execute a Python script on the compromised servers. CVE-2020-28188 The vulnerability is caused by a lack of input validation in the “event” parameter in the “makecvs” PHP page (/include/makecvs.php). This allows a remote unauthenticated attacker to inject OS commands, and gain control of the servers using TerraMaster TOS (versions prior to 4.2.06). | FreakOut is an attack campaign that utilizes three vulnerabilities, including some newly released, to compromise different servers. The threat actor behind the attack, named “Freak”, managed to infect many devices in a short period of time, and incorporated them into a botnet, which in turn is used for DDoS attacks and crypto-mining.
CVE-2020-7961 The vulnerability is a Java unmarshalling vulnerability via JSONWS in Liferay Portal (in versions prior to 7.2.1 CE GA2). Exploiting the vulnerability lets the attacker provide a malicious object, that when unmarshalled, allows remote code execution. | FreakOut is an attack campaign that utilizes three vulnerabilities, including some newly released, to compromise different servers. The threat actor behind the attack, named “Freak”, managed to infect many devices in a short period of time, and incorporated them into a botnet, which in turn is used for DDoS attacks and crypto-mining.
Earlier versions of Necro exploited the following vulnerabilities in web applications: ... Laravel RCE (CVE-2021-3129) ...
Earlier versions of Necro exploited the following vulnerabilities in web applications: ... WebLogic RCE (CVE-2020-14882) ...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FreakOut is an attack campaign that utilizes three vulnerabilities, including some newly released, to compromise different servers. The threat actor behind the attack, named “Freak”, managed to infect many devices in a short period of time, and incorporated them into a botnet, which in turn is used for DDoS attacks and crypto-mining.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
...designed to evade detection using a polymorphic engine and a user-mode rootkit that hides malicious files dropped on compromised systems.
All the connection credentials are obfuscated and encoded in the code itself multiple times, and are generated using multiple functions.
Each infected device is configured to communicate with a hardcoded C2 server. At the initial connection to the server, the conversation begins with the client sending a “NICK message”...
In a later variant, Xmrig causes the victim’s device to engage in coin-mining.
The malware's core functionality enables operators to launch DDoS attacks...
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet reported exploiting newly disclosed vulnerabilities (including CVE-2021-3007) to compromise vulnerable systems and expand its infected node population.
Referenced as a botnet associated with exploitation of CVE-2021-3007 (Laminas/Zend Framework insecure deserialization RCE) and flagged in KEV context.
A multi-platform Python-based malware targeting Windows and Linux that self-spreads by exploiting multiple vulnerabilities and brute-forcing SSH credentials, enrolls victims into an IRC botnet, and enables DDoS attacks, backdoor access, traffic sniffing/exfiltration, and deployment of XMRig miners for Monero mining.
At the time of writing, we note that two security vendors have reported Necro botnet PythonCryptoMinter FreakOut, but they both describe the second version that has stopped spreading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.