NetBus is a legacy remote access trojan (RAT) from the late 1990s, publicly available by 1998 and commonly cited alongside Back Orifice and Sub7 as an early-generation RAT. It targeted Windows systems, with analysis references indicating that legacy environments such as Windows XP or Windows 95 may be required to study or execute it. NetBus is associated with fixed network port usage, especially TCP port 12345, which is repeatedly identified as a characteristic port for the malware.
The malware is described as part of the early RAT era in which the attacker operated a client application and the compromised machine ran the victim-side "server" payload. Content on early RAT architecture indicates these families commonly transferred data in plaintext, were often written in Delphi or VB6, and used static patching of server stubs to embed configuration such as IP address and bind port rather than later builder-based approaches. NetBus is specifically named as an example of this early RAT generation.
The provided content also places NetBus in historical intrusion scenarios where mass exploitation could be used to deploy backdoors. In particular, security reporting on a 2000 Microsoft Outlook/Outlook Express Date-field buffer overflow noted that attackers could potentially install malware such as NetBus without requiring victims to open attachments; Outlook users could be compromised by reading a malicious message, and Outlook Express users could be compromised even without reading it. Experts warned that a single well-placed email could infect thousands of recipients and deploy backdoors including NetBus.
High-confidence indicators and identifiers mentioned in the content include the malware name NetBus/netbus and its characteristic TCP port 12345. The content does not provide additional family-specific capabilities beyond its classification as an early RAT/backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
A newly discovered vulnerability in Microsoft's Outlook and Outlook Express programs leave thousands of computers open to attack from malicious email... The vulnerability doesn't require any attachment to the email; Outlook users need only read a message to be hit. Outlook Express users are even more vulnerable, and can fall prey to malicious code without reading the message, or even being at their computer when it comes in.
The bug is a classic "buffer overflow" error in the section of Outlook that parses the Date field of each incoming email. By padding the date with a long string of characters, an attacker can escape from the area of memory reserved for storing it, and into a section that executes instructions.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early-generation remote access trojan from the 1990s. The article groups it with RATs that transferred data in plain text, used direct client/server control models, and generated payload executables via static patching of an existing server stub.
Legacy malware referenced as an example of an older sample that may require legacy Windows environments for analysis.
Named trojan referenced as a publicly available example; content implies remote control/administration style trojan but provides no technical specifics here.
A remote access/backdoor tool cited as malware that could be deployed at scale through exploitation of the Outlook bug.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.