Netcat is a legitimate command-line networking utility for reading from and writing to network connections. It is frequently repurposed by threat actors as lightweight reverse-shell and command-and-control tooling, providing interactive remote access, socket-based tunneling, and data transfer without requiring a bespoke backdoor. Observed abuse includes deployment following exploitation of internet-facing applications, use alongside cryptomining malware to enable follow-on compromise or information theft, and masquerading of renamed Windows binaries as legitimate updates. Netcat has been associated with activity attributed to APT32, Ember Bear, ransomware-related exploitation of managed file-transfer products, and intrusion clusters assessed to overlap with Sandworm. It has been used on both Windows and Unix-like systems, including Linux targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“…as well as Cobalt Strike and Netcat can be found.”
"...an unauthorized party used a previously unknown, zero-day remote code execution (RCE) vulnerability to access certain GoAnywhere customers’ systems. This vulnerability was assigned CVE-2023-0669."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-11823 deployed a Netcat reverse shell through a malicious license.tmp file executed by package_info.pl.
...Netcat... may have been used by the attackers as well.
Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST).
19 distinct techniques documented for this family, organized by ATT&CK tactic.
“We built a container image with netcat installed, deployed it as an AgentCore Runtime, and connected back with a reverse shell.”
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Its simplicity masks a surprising versatility: it can copy files, tunnel traffic, relay ports, scan networks, and sometimes even replace more complex post-exploitation tools.
UAT-11823 modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure.
Finally, the stage 4 payload executes the reverse shell script located at /data/data/com.termux/_rev.sh , establishing a root reverse shell connection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-line networking tool used in this activity to establish a reverse shell.
NetCat is a legitimate network utility often abused by attackers as a backdoor or for lateral movement, file transfer, and remote command execution.
A legitimate networking utility frequently abused by attackers to create bind/reverse shells and facilitate remote command execution after initial exploitation (here, via ShellShock).
Network utility used as a backdoor-like tool for remote shell access and data transfer after compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.