FREEFIRE is a lightweight .NET backdoor identified by Mandiant that uses Slack as its command-and-control channel. It communicates with a hard-coded Slack channel to retrieve commands and upload responses, and it supports loading arbitrary .NET assemblies that are Base64-encoded and delivered via Slack chat comments. Mandiant observed FREEFIRE in post-compromise activity following exploitation of Citrix NetScaler ADC and NetScaler Gateway CVE-2023-4966, where attackers hijacked authenticated sessions by stealing NetScaler AAA session cookies from appliance memory. In those intrusions, FREEFIRE was deployed alongside other post-exploitation activity including Active Directory reconnaissance with net.exe, internal network scanning with SoftPerfect netscan.exe, credential theft including LSASS dumping and suspected Mimikatz usage, lateral movement via RDP, and use of RMM tools such as Atera, AnyDesk, and SplashTop. Mandiant tracked multiple UNC clusters exploiting the vulnerability across legal and professional services, technology, and government organizations in the Americas, EMEA, and APJ, but the provided content does not attribute FREEFIRE to a specific named threat actor. No specific FREEFIRE file hashes, domains, or other malware-specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.