NETWIRE

MITRE ATT&CK: S0198 View on attack.mitre.org

Aliases: NETWIRE

First seen
2012-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows, linux, macos
Related IoCs
4723 (4678 malicious)
Last IoC activity
2026-09-02 04:25:30
Profile updated
2026-07-07 12:42:30

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.

Recent IoC activity

4,704 malicious indicators in Maltiverse are attributed to NETWIRE (S0198). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-09-02_4f7fcea909391957a0ff9de6e7d061ae_agent-tesla_darkgate_elex_hawkeye... 2026-09-03 1
hostname dejoma.camdvr.org 2026-09-03 1
file sample 2026-04-19_2cf68a14e8ce73d560e8dbd2551d2f30_agent-tesla_elex_hawkeye_maze_net... 2026-09-03 1
file sample 2026-09-02_54655eb0bdf0842ad957e8922a42ca31_agent-tesla_elex_hawkeye_maze_net... 2026-09-03 1
hostname dnsresolve.srs8l2.com 2026-09-03 1
hostname stussy.ooguy.com 2026-09-03 1
hostname nerosta.giize.com 2026-09-03 1
hostname javaupdate.100chickens.biz 2026-09-03 1
file sample 76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a.bin 2026-09-03 2
file sample 2026-09-02_5e655c772de27a108004f69d270f0927_agent-tesla_darkgate_elex_hawkeye... 2026-09-03 1
file sample 2026-09-02_64535f7892461960975ca9fbd808fe0c_agent-tesla_elex_hawkeye_maze_net... 2026-09-03 1
file sample 2026-09-02_6e75898f91803a9f0ec1d0e2b97bac32_agent-tesla_elex_hawkeye_maze_net... 2026-09-02 1
file sample 2026-09-02_769b7a00bb8aee85a021e8bea8ccfceb_agent-tesla_darkgate_elex_hawkeye... 2026-09-02 1
hostname sftp21.duckdns.org 2026-09-02 1
file sample 2026-09-02_a3ec2dd59968d45bc98a878399ddaa91_agent-tesla_darkgate_elex_hawkeye... 2026-09-02 1
file sample 2026-09-02_b21ec6a71e6f9cf3aadd5d58eae8f3c1_agent-tesla_darkgate_elex_hawkeye... 2026-09-02 1
file sample 33e862e2b9c1b2dc6cb863ad9717e5d6bb27633eab47e4dfdeaf2c1c6189dfa3.bin 2026-09-02 2
file sample 2026-09-02_da8fc2997b2d5b4d9ccaa98f4c43058c_agent-tesla_darkgate_elex_hawkeye... 2026-09-02 1
file sample 2026-09-02_ef9a40ba4e4deae5535271f21fbbb779_agent-tesla_darkgate_elex_hawkeye... 2026-09-02 1
file sample x75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0.exe 2026-09-02 2

Detection coverage

  • 851 Sigma rules

Malware & tools used

  • Proxy (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Software Packing (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Malicious File (attack-pattern)
  • Malicious Link (attack-pattern)
  • Automated Collection (attack-pattern)
  • XDG Autostart Entries (attack-pattern)
  • Visual Basic (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • PowerShell (attack-pattern)
  • Process Injection (attack-pattern)
  • Cron (attack-pattern)
  • Fileless Storage (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Unix Shell (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Web Service (attack-pattern)

Used by threat actors

Reports & references

  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • brighttalk.com — 275683 (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Netwire (report)
  • intego.com — Fbi Shuts Down 11 Year Old Netwire Rat Malware (report)
  • secureworks.com — Netwire Rat Steals Payment Card Data (report)
  • MITRE ATT&CK — S0198 (report)
  • McAfee — Netwire Rat Behind Recent Targeted Attacks (report)

External references