N3Cr0m0rPh
Aliases: FreakOut, Necro
- First seen
- 2015-01-01 00:00:00
- Malware type
- botnet, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 13:05:46
Targeted industries: financial-services education-and-nonprofits technology-and-telecommunications
Context
An IRC bot written in (obfuscated) Python code. Distributed in attack campaign FreakOut, written by author Freak/Fl0urite and development potentially dating back as far as 2015.
Reports & references
- blog.netlab.360.com — Necro Upgrades Again Using Tor Dynamic Domain Dga And Aiming At Both Windows Linux (report)
- blog.netlab.360.com — Gafgtyt Tor And Necro Are On The Move Again (report)
- lacework.com — The Kek Security Network (report)
- lacework.com — The Kek Security Network (report)
- malpedia.caad.fkie.fraunhofer.de — Py.N3Cr0M0Rph (report)
- blog.netlab.360.com — Not Really New Pyhton Ddos Bot N3Cr0M0Rph Necromorph (report)
- Cisco Talos — Necro Python Bot Adds New Tricks (report)
- research.checkpoint.com — Freakout Leveraging Newest Vulnerabilities For Creating A Botnet (report)
- lacework.com — Keksec Tsunami Ryuk (report)
- lacework.com — Spytech Necro Keksecs Latest Python Malware (report)
- blogs.juniper.net — Necro Python Botnet Goes After Vulnerable Visualtools Dvr (report)
- twitter.com — 1392089568384454657 (report)
- twitter.com — 1393384128456794116 (report)
- github.com — Keksec (report)
- bleepingcomputer.com — Freakout Malware Worms Its Way Into Vulnerable Vmware Servers (report)
- blog.netlab.360.com — Necro (report)