N3Cr0m0rPh

Aliases: FreakOut, Necro

First seen
2015-01-01 00:00:00
Malware type
botnet, cryptominer
Family
Malware family
Profile updated
2026-07-07 13:05:46

Targeted industries: financial-services education-and-nonprofits technology-and-telecommunications

Context

An IRC bot written in (obfuscated) Python code. Distributed in attack campaign FreakOut, written by author Freak/Fl0urite and development potentially dating back as far as 2015.

Reports & references

  • blog.netlab.360.com — Necro Upgrades Again Using Tor Dynamic Domain Dga And Aiming At Both Windows Linux (report)
  • blog.netlab.360.com — Gafgtyt Tor And Necro Are On The Move Again (report)
  • lacework.com — The Kek Security Network (report)
  • lacework.com — The Kek Security Network (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.N3Cr0M0Rph (report)
  • blog.netlab.360.com — Not Really New Pyhton Ddos Bot N3Cr0M0Rph Necromorph (report)
  • Cisco Talos — Necro Python Bot Adds New Tricks (report)
  • research.checkpoint.com — Freakout Leveraging Newest Vulnerabilities For Creating A Botnet (report)
  • lacework.com — Keksec Tsunami Ryuk (report)
  • lacework.com — Spytech Necro Keksecs Latest Python Malware (report)
  • blogs.juniper.net — Necro Python Botnet Goes After Vulnerable Visualtools Dvr (report)
  • twitter.com — 1392089568384454657 (report)
  • twitter.com — 1393384128456794116 (report)
  • github.com — Keksec (report)
  • bleepingcomputer.com — Freakout Malware Worms Its Way Into Vulnerable Vmware Servers (report)
  • blog.netlab.360.com — Necro (report)

External references