NetWalker, also known as Mailto and Koko, was a financially motivated ransomware-as-a-service operation active from 2019 into 2021 that became one of the major big-game ransomware threats of that period. The operation combined enterprise-focused network intrusions with file encryption and later adopted double extortion, stealing data before encryption and threatening public release through a leak site if victims refused to pay. NetWalker affiliates attacked hundreds of organizations worldwide, with reporting indicating at least 305 victims across 27 countries and a concentration of victims in the United States. NetWalker targeted a broad range of sectors, including healthcare, higher education, school districts, municipalities, law enforcement, emergency services, and private companies. Healthcare organizations were specifically targeted during the COVID-19 period. Publicly reported victims and targeting patterns also show interest in large enterprises and critical business operations, including universities and energy-sector organizations. The operation used an affiliate model in which operators recruited partners on underground forums to conduct intrusions and spam-based distribution, while the core administrators supplied updated ransomware builds, administrative panels, automated payment infrastructure, leak-blog support, and services intended to reduce antivirus detection. Affiliates reportedly received a large share of ransom proceeds, and the program explicitly sought collaborators with access to large enterprise networks. NetWalker maintained a victim-shaming site and used stolen unencrypted files as leverage, making it a prominent practitioner of double extortion. Initial access and intrusion methods associated with NetWalker included exposed or weakly secured RDP, exploitation of internet-facing enterprise software and VPN appliances, and use of vulnerabilities such as CVE-2019-11510 and CVE-2019-18935. Reporting also links the group to exploitation of Oracle WebLogic and Apache Tomcat in some intrusions. During operations, NetWalker actors used remote administration tools, custom PowerShell scripts, legitimate security-product uninstallers, and privilege-escalation exploits including CVE-2020-0796. The malware deleted shadow copies, could encrypt mapped drives and shared network resources, and employed defense-evasion measures including unique builds and process injection into explorer.exe. NetWalker is widely associated with the Russian-speaking cybercrime ecosystem. Its affiliate rules prohibited attacks on Russia and other Commonwealth of Independent States countries, a pattern commonly seen among ransomware groups seeking to avoid local law-enforcement attention. Law-enforcement action in January 2021 disrupted the operation’s leak-site infrastructure, and prosecutions later targeted prominent affiliates and conspirators, contributing to the group’s collapse. NetWalker remains notable as a leading example of the transition from conventional ransomware to mature RaaS-enabled double-extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11510 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11539 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-1579 (Global Protect)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-19781 (Citrix)
In a trove of malicious files discovered while investigating a malware campaign from Netwalker, the researchers also found that the attacker also leveraged several vulnerabilities for privilege escalation. One of them is CVE-2020-0796, for which there is proof-of-concept exploit code released for local privilege escalation. It can also be exploited for remote code execution, but the code for this is not currently available to the public.
2 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
A ransomware operation whose affiliates may have integrated with Conti after law-enforcement disruption, using TrickBot distribution and Conti-provided tooling.
Ransomware operation whose proceeds were processed/laundered via Garantex per U.S. Treasury.
Referenced as a ransomware threat group whose proceeds were laundered via the Garantex cryptocurrency exchange.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.