NetWire RC

Aliases: NetWeird, NetWire, Recam

First seen
2012-08-01 00:00:00
Malware type
rat, credential-stealer, keylogger
Family
Malware family
Last IoC activity
2026-07-22 02:36:20
Profile updated
2026-07-07 12:42:27

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well. Keylog files are stored on the infected machine in an obfuscated form. The algorithm is: for i in range(0,num_read): buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Netwire (yara-rule)
  • MALPEDIA_Win_Netwire_Auto (yara-rule)

Reports & references

  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • secureworks.com — Cobalt Trinity (report)
  • sentinelone.com — Modifiedelephant Apt And A Decade Of Fabricating Evidence (report)
  • Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q3 2021 (report)
  • marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
  • proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
  • research.loginsoft.com — From Innocence To Malice The Onenote Malware Campaign Uncovered (report)
  • blog.morphisec.com — Revealing The Snip3 Crypter A Highly Evasive Rat Loader (report)
  • news.sophos.com — Raticate (report)
  • research.checkpoint.com — Following The Scent Of Trickgate 6 Year Old Packer Used To Deploy The Most Wanted Malware (report)
  • zscaler.com — Catching Rats Over Custom Protocols (report)
  • gdatasoftware.com — Global Pandemic Remcos Tesla Netwire (report)
  • threatpost.com — 178422 (report)
  • bleepingcomputer.com — Unskilled Hacker Linked To Years Of Attacks On Aviation Transport Sectors (report)
  • Cisco Talos — Nanocore Netwire And Asyncrat Spreading (report)
  • fortinet.com — Threat Actors Prey On Eager Travelers (report)

External references