Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Necro scans for and propagates through Laravel RCE (CVE-2021-3129); its exploit establishes a reverse shell that downloads a Bash script, Necro, Gafgyt_tor, and a mining program.
The Gafgyt_tor botnet is mainly propagated through Telnet weak passwords and three vulnerabilities, including D-Link RCE (CVE-2019-16920). | Since February 15, 2021, 360Netlab's BotMon system has continuously detected a new variant of the Gafgyt family, which uses Tor for C2 communication to hide the real C2 and encrypts sensitive strings in the samples. ... we named the variant Gafgyt_tor.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Laravel exploit's downloaded script is described as downloading and executing Gafgyt_tor; the report also states that Gafgyt_tor and Necro are released by the same KekSec group.
Since February 15, 2021, 360Netlab's BotMon system has continuously detected a new variant of the Gafgyt family, which uses Tor for C2 communication to hide the real C2 and encrypts sensitive strings in the samples. ... we named the variant Gafgyt_tor.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“In the sample captured on February 24 we found that the function name was obfuscated as a random string,” indicating efforts to strengthen anti-analysis and detection evasion.
217 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Tor-enabled Gafgyt variant propagated by Necro against specific Linux targets. It is associated with the KekSec group and uses Tor to obscure C2 infrastructure.
A Gafgyt variant that compromises IoT devices through Telnet weak passwords and exploits, then performs scanning and DDoS attacks. It routes C2 traffic through embedded Tor proxy nodes to reach a .onion C2, encrypts sensitive strings, and supports dynamically changing its payload-download server through the LDSERVER command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.