NetWalker, also known as Mailto and Koko, was a financially motivated ransomware-as-a-service operation active from 2019 until major law-enforcement disruption in early 2021. It evolved from conventional file-encryption ransomware into a double-extortion enterprise that stole data before encryption and used a leak site to pressure victims. The operation recruited affiliates on Russian-language cybercrime forums, provided continuously updated ransomware builds, administrative panels, automated payment infrastructure, and a victim-shaming blog, and offered unusually high revenue shares to intrusion partners. Affiliates were tasked with gaining access to victim environments and deploying the ransomware, while the core operators maintained the malware and extortion platform. NetWalker targeted organizations worldwide, with a majority of known victims in the United States. Victim sectors included government entities, municipalities, hospitals, law enforcement, emergency services, school districts, colleges, universities, and private companies. Healthcare organizations were specifically targeted during the COVID-19 period. The group also hit large enterprises and critical business operations, including universities and energy-sector organizations. Observed initial access and intrusion methods included exploitation of exposed remote access services and internet-facing enterprise software, including Pulse Secure VPN, Oracle WebLogic, Apache Tomcat, and Telerik UI, as well as insecure RDP configurations. NetWalker operations also used legitimate remote-access tools, custom PowerShell scripts, public-code-repository tooling, and legitimate security-product uninstallers to disable defenses. Reported post-compromise behavior included privilege escalation, antivirus evasion, encryption of mapped drives and shared network resources, deletion of shadow copies, and use of process injection into explorer.exe for execution and cleanup. The malware family used Salsa20 encryption and later shifted from email-based ransom communications to Tor-based payment portals. NetWalker operated a leak site and used stolen data as leverage alongside encryption, making it a prominent early adopter of double extortion among major ransomware groups. Its affiliate program prohibited targeting Russia and other Commonwealth of Independent States countries, a pattern commonly associated with Russian-speaking cybercriminal ecosystems. The operation generated tens of millions of dollars in ransom payments and was linked to hundreds of victims across dozens of countries before U.S. and Bulgarian authorities seized its leak-site infrastructure. Known affiliates and associated actors were later prosecuted in Canada and the United States, and reporting has suggested some former NetWalker affiliates later migrated into other ransomware ecosystems, including Conti.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
A ransomware operation whose affiliates may have integrated with Conti after law-enforcement disruption, using TrickBot distribution and Conti-provided tooling.
Ransomware operation whose proceeds were processed/laundered via Garantex per U.S. Treasury.
Referenced as a ransomware threat group whose proceeds were laundered via the Garantex cryptocurrency exchange.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.