NetTraveler
MITRE ATT&CK: S0033 View on attack.mitre.org
Aliases: TravNet, NetTraveler
- First seen
- 2005-01-01 00:00:00
- Malware type
- spyware, backdoor
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-06-15 10:45:04
- Profile updated
- 2026-07-07 15:44:16
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities education-and-nonprofits financial-services
Targeted regions: country_code:cn country_code:ru country_code:kz country_code:in country_code:ir
Context
NetTraveler is malware that has been used in multiple cyber espionage campaigns for basic surveillance of victims. The earliest known samples have timestamps back to 2005, and the largest number of observed samples were created between 2010 and 2013.
Detection coverage
- 1 YARA rules
- 4 Sigma rules
Malware & tools used
- Application Window Discovery (attack-pattern)
- Keylogging (attack-pattern)
Used by threat actors
- TA459 (threat-actor)
Detection rules
- MALPEDIA_Win_Nettraveler_Auto (yara-rule)
Reports & references
- proofpoint.com — Nettraveler Apt Targets Russian European Interests (report)
- media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)
- web.archive.org — Globalthreatintelreport (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nettraveler (report)
- cybergeeks.tech — Dissecting Apt21 Samples Using A Step By Step Approach (report)
- MITRE ATT&CK — S0033 (report)
- web.archive.org — Kaspersky The Net Traveler Part1 Final (report)