Netwalker

MITRE ATT&CK: S0457 View on attack.mitre.org

Aliases: Netwalker

First seen
2019-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
49 (49 malicious)
Last IoC activity
2026-08-21 03:52:54
Profile updated
2026-07-07 12:37:39

Targeted industries: healthcare-and-pharmaceutical government-and-public-sector education-and-nonprofits financial-services

Context

Netwalker is fileless ransomware written in PowerShell and executed directly in memory.

Recent IoC activity

49 malicious indicators in Maltiverse are attributed to Netwalker (S0457). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-08-21_d424d90b9b27ecea4b4fca38855bb251_elex_mailto 2026-08-21 1
file sample 2026-08-20_692d5caf5cf65ce53a72514329384aae_babuk_elex_mailto 2026-08-21 1
file sample 2026-08-20_ad277243ba84b4291e5ccb11e90667f2_babuk_elex_mailto 2026-08-20 1
file sample 525a7682005cdcb2867f2a5b7e927f983a8fde08edc031c00e952acbdd1f6cf0 2026-08-12 1
file sample 9000db5c681c89f0fd609f538b0c73c86362e63c821c667c57d877c1a3ec98da 2026-08-12 1
file sample 46e360d30ecd26e417be85fa3810ff6a043b2b16b0fac4a044651921c795ad73 2026-08-12 1
file sample fddaad236d475bf897ac1eb80b786a694eee7e0a9ff1a44de435e04b41a0b7b7 2026-08-12 1
file sample 159b7e7963db5c8f5b373817d2fd5f240a34eec916d0747f3a8c0ea6a05f3d9e 2026-08-12 1
file sample 8cef4b188c641a0237837eda89a68000152ec159cdb111fe22c3aeaafa42e8ad 2026-08-12 1
file sample e5141d9862a6c3f572f3387f852d684718926d0d336fd185a94be2640c13feb7 2026-08-12 1
file sample af1d351e47de1a8dc75a3d6c448d8c9352cab0bd274afd9a3d56c0d1fe65547d 2026-08-12 1
file sample 6369718b0b010e0c5a68299467a8da609d62683342ae9ea5ed61662b54e6848b 2026-08-12 1
file sample 291c0e34a302b27d0349c77be3a8a24a135ba6d398571e836c93d7dcc9ff4149 2026-08-12 1
file sample 79a3a1b421fc6c68deef75cea74ac659bb589fc3d7efb58f14c8a4f883cdd96d 2026-08-12 1
file sample 3735bfd7b52c714a943f7c74327a9b8ec6302a858e1f3b4ba31ccb638166a3b9 2026-08-12 1
file sample c924b4111d2f268cd9b1944d419f154a4f72dc85c0b8ef929ef674a211939611 2026-08-12 1
file sample 726eee3d11e518848caf41acf4b1db2a9687726d5ff1106911138bf5a7ead0d2 2026-08-12 1
file sample c23a696a65da5ca95c1b78984d0ec7636bf5de53d27727f3d59e65c161033639 2026-08-12 1
file sample 96e21b7407ed4f95b20b62e508e4027ad02cc2808736a56828fd6de58ab1f257 2026-08-12 1
file sample 5c234cb3a25b3e0ab0946d45931ff1705138d561ab1f765c8f44f34ac0f489c7 2026-08-12 1

Detection coverage

  • 3 YARA rules
  • 729 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Native API (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Service Execution (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Service Stop (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)

Detection rules

  • TRELLIX_ARC_Netwalker_Ransomware (yara-rule)
  • TRELLIX_ARC_Netwalker_Signed (yara-rule)
  • TRELLIX_ARC_Netwalker (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — Analysis Of Ecrime Menu Style Toolkits (report)
  • CrowdStrike — Reportcsit 20081E (report)
  • CrowdStrike — Big Game Hunting On The Rise Again According To Ecrime Index (report)
  • cti-league.com — Cti League Darknet Report 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • Microsoft — Microsoft Digital Defense Report 2020 September (report)
  • ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • sites.temple.edu — Ci Rw Attacks (report)
  • therecord.media — Darkside Gang Estimated To Have Made Over 90 Million From Ransomware Attacks (report)
  • therecord.media — Ransomwhere Project Wants To Create A Database Of Past Ransomware Payments (report)
  • bleepingcomputer.com — Darkside Ransomware Made 90 Million In Just Nine Months (report)
  • coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
  • cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
  • hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)
  • Microsoft — Ransomware Groups Continue To Target Healthcare Critical Services Heres How To Reduce Risk (report)
  • paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
  • pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
  • ESET — Eset Threat Report Q22020 (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)

External references