Netwalker
MITRE ATT&CK: S0457 View on attack.mitre.org
Aliases: Netwalker
- First seen
- 2019-08-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 49 (49 malicious)
- Last IoC activity
- 2026-08-21 03:52:54
- Profile updated
- 2026-07-07 12:37:39
Targeted industries: healthcare-and-pharmaceutical government-and-public-sector education-and-nonprofits financial-services
Context
Netwalker is fileless ransomware written in PowerShell and executed directly in memory.
Recent IoC activity
49 malicious indicators in Maltiverse are attributed to Netwalker (S0457). The 20 most recently updated:
Detection coverage
- 3 YARA rules
- 729 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Information Discovery (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Windows Command Shell (attack-pattern)
- Command Obfuscation (attack-pattern)
- Security Software Discovery (attack-pattern)
- Embedded Payloads (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- PowerShell (attack-pattern)
- Native API (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Service Execution (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Service Stop (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
Detection rules
- TRELLIX_ARC_Netwalker_Ransomware (yara-rule)
- TRELLIX_ARC_Netwalker_Signed (yara-rule)
- TRELLIX_ARC_Netwalker (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Analysis Of Ecrime Menu Style Toolkits (report)
- CrowdStrike — Reportcsit 20081E (report)
- CrowdStrike — Big Game Hunting On The Rise Again According To Ecrime Index (report)
- cti-league.com — Cti League Darknet Report 2021 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- Microsoft — Microsoft Digital Defense Report 2020 September (report)
- ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- sites.temple.edu — Ci Rw Attacks (report)
- therecord.media — Darkside Gang Estimated To Have Made Over 90 Million From Ransomware Attacks (report)
- therecord.media — Ransomwhere Project Wants To Create A Database Of Past Ransomware Payments (report)
- bleepingcomputer.com — Darkside Ransomware Made 90 Million In Just Nine Months (report)
- coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
- cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
- hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)
- Microsoft — Ransomware Groups Continue To Target Healthcare Critical Services Heres How To Reduce Risk (report)
- paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
- pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
- ESET — Eset Threat Report Q22020 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)