NetTraveler

MITRE ATT&CK: S0033 View on attack.mitre.org

Aliases: TravNet, NetTraveler

First seen
2005-01-01 00:00:00
Malware type
spyware, backdoor
Family
Malware family
Operating systems
windows
Last IoC activity
2026-06-15 10:45:04
Profile updated
2026-07-07 15:44:16

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities education-and-nonprofits financial-services

Targeted regions: country_code:cn country_code:ru country_code:kz country_code:in country_code:ir

Context

NetTraveler is malware that has been used in multiple cyber espionage campaigns for basic surveillance of victims. The earliest known samples have timestamps back to 2005, and the largest number of observed samples were created between 2010 and 2013.

Detection coverage

  • 1 YARA rules
  • 4 Sigma rules

Malware & tools used

  • Application Window Discovery (attack-pattern)
  • Keylogging (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Nettraveler_Auto (yara-rule)

Reports & references

  • proofpoint.com — Nettraveler Apt Targets Russian European Interests (report)
  • media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)
  • web.archive.org — Globalthreatintelreport (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nettraveler (report)
  • cybergeeks.tech — Dissecting Apt21 Samples Using A Step By Step Approach (report)
  • MITRE ATT&CK — S0033 (report)
  • web.archive.org — Kaspersky The Net Traveler Part1 Final (report)

External references