NETWIRE
MITRE ATT&CK: S0198 View on attack.mitre.org
Aliases: NETWIRE
- First seen
- 2012-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows, linux, macos
- Related IoCs
- 4723 (4678 malicious)
- Last IoC activity
- 2026-09-02 04:25:30
- Profile updated
- 2026-07-07 12:42:30
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.
Recent IoC activity
4,704 malicious indicators in Maltiverse are attributed to NETWIRE (S0198). The 20 most recently updated:
Detection coverage
- 851 Sigma rules
Malware & tools used
- Proxy (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Software Packing (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Malicious File (attack-pattern)
- Malicious Link (attack-pattern)
- Automated Collection (attack-pattern)
- XDG Autostart Entries (attack-pattern)
- Visual Basic (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- Process Injection (attack-pattern)
- Cron (attack-pattern)
- Fileless Storage (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Unix Shell (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Spearphishing Link (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Service (attack-pattern)
Used by threat actors
- The White Company (threat-actor)
- APT33 (threat-actor)
- SilverTerrier (threat-actor)
- TA2541 (threat-actor)
Reports & references
- Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
- brighttalk.com — 275683 (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Netwire (report)
- intego.com — Fbi Shuts Down 11 Year Old Netwire Rat Malware (report)
- secureworks.com — Netwire Rat Steals Payment Card Data (report)
- MITRE ATT&CK — S0198 (report)
- McAfee — Netwire Rat Behind Recent Targeted Attacks (report)