Net Crawler

MITRE ATT&CK: S0056 View on attack.mitre.org

Aliases: NetC, Net Crawler

First seen
2014-01-01 00:00:00
Malware type
worm, credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:28:11

Targeted industries: government-and-public-sector financial-services energy-and-utilities

Context

Net Crawler is an intranet worm capable of extracting credentials using credential dumpers and spreading to systems on a network over SMB by brute forcing accounts with recovered passwords and using PsExec to execute a copy of Net Crawler.

Detection coverage

  • 149 Sigma rules

Malware & tools used

  • Password Cracking (attack-pattern)
  • Service Execution (attack-pattern)
  • LSASS Memory (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • MITRE ATT&CK — S0056 (report)
  • web.archive.org — Cylance Operation Cleaver Report (report)

External references