NetWire RC
Aliases: NetWeird, NetWire, Recam
- First seen
- 2012-08-01 00:00:00
- Malware type
- rat, credential-stealer, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:36:20
- Profile updated
- 2026-07-07 12:42:27
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Context
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well. Keylog files are stored on the infected machine in an obfuscated form. The algorithm is: for i in range(0,num_read): buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Netwire (yara-rule)
- MALPEDIA_Win_Netwire_Auto (yara-rule)
Reports & references
- Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- secureworks.com — Cobalt Trinity (report)
- sentinelone.com — Modifiedelephant Apt And A Decade Of Fabricating Evidence (report)
- Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q3 2021 (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
- research.loginsoft.com — From Innocence To Malice The Onenote Malware Campaign Uncovered (report)
- blog.morphisec.com — Revealing The Snip3 Crypter A Highly Evasive Rat Loader (report)
- news.sophos.com — Raticate (report)
- research.checkpoint.com — Following The Scent Of Trickgate 6 Year Old Packer Used To Deploy The Most Wanted Malware (report)
- zscaler.com — Catching Rats Over Custom Protocols (report)
- gdatasoftware.com — Global Pandemic Remcos Tesla Netwire (report)
- threatpost.com — 178422 (report)
- bleepingcomputer.com — Unskilled Hacker Linked To Years Of Attacks On Aviation Transport Sectors (report)
- Cisco Talos — Nanocore Netwire And Asyncrat Spreading (report)
- fortinet.com — Threat Actors Prey On Eager Travelers (report)