NetWalker is a ransomware family and ransomware-as-a-service (RaaS) operation. The provided content states that it encrypts files on infected machines to extort victims, deletes Shadow Volumes to inhibit recovery, and can use WMI to delete shadow copies. It can detect and terminate active security software-related processes on infected systems, indicating defense-evasion behavior. NetWalker has been described as written in PowerShell, executed directly in memory to avoid detection, with its DLL embedded in the PowerShell script in hex format; related reporting also notes multiple layers of PowerShell obfuscation including Base64, hexadecimal encoding, XOR encryption, and obfuscated functions and variables. The content also references a registry artifact in the form of an added entry under HKEY_CURRENT_USER\SOFTWARE{8 random characters}. Infection and access vectors mentioned in the content include coronavirus-themed phishing lures, including attacks against Spanish hospitals, .vbs attachments in COVID-19-themed emails, exploitation of Telerik UI for ASP.NET AJAX vulnerability CVE-2019-18935, and compromises of misconfigured IIS-based applications followed by use of tools such as Mimikatz and PsExec before ransomware deployment. NetWalker is associated in the content with the threat actor Circus Spider, which is described as generally targeting hospitals in the U.S. and Spain. Additional ecosystem references note that UNC2628 was believed to partner with multiple RaaS services including NetWalker, and that law enforcement seized NetWalker data leak and payment sites in January 2021, with other reporting in the content referring to the arrest of an affiliate and the program's subsequent demise. The content also notes that Garantex received cryptocurrency proceeds from Russia-linked ransomware attacks including NetWalker.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Versions prior to R1 2020 (2020.1.114) are susceptible to remote code execution attacks... There were two malware campaigns associated with this vulnerability: Netwalker Ransomware and Blue Mockbird Monero Cryptocurrency-mining. | There were two malware campaigns associated with this vulnerability: • Netwalker Ransomware and • Blue Mockbird Monero Cryptocurrency-mining.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content includes multiple examples of PowerShell being used to decode or deobfuscate payloads and commands, such as 'the threat actors deobfuscated encoded PowerShell commands' and 'OilRig macro has run a PowerShell command to decode file contents.'
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
Citrix ADC maintains a vulnerable Perl script (newbm.pl) that, when accessed via HTTP POST request ... allows local operating system (OS) commands to execute. Attackers can use this functionality to upload/execute command and control (C2) software ... and gain unauthorized access to the OS.
"Anchor can create and execute services to load its payload"; "APT32's backdoor has used Windows services as a way to execute its malicious payload"; "Ragnar Locker has used sc.exe to execute a service that it creates"; "Shamoon creates a new service named 'ntssrv' to execute the payload"
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
"APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection"; "IcedID has called ZwWriteVirtualMemory... ZwQueueApcThread... to inject itself into a remote process"; "Havoc can use NtAllocateVirtualMemory and NtCreateThreadEx to aid process injection"
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
"APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection"; "IcedID has called ZwWriteVirtualMemory... ZwQueueApcThread... to inject itself into a remote process"; "Havoc can use NtAllocateVirtualMemory and NtCreateThreadEx to aid process injection"
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
“APT41 used certutil to download additional files.”; “Astaroth uses certutil and BITSAdmin to download additional malware.”; “CARROTBAT… download and execute a remote file via certutil.”; “Netwalker… used psexec and certutil to retrieve the Netwalker payload.”
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
"Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses," "Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk," and "Turla has also used PowerShell scripts to load and execute malware in memory."
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
"PsExec ... can be used to execute binaries on remote systems using a temporary Windows service"; "RemoteCMD can execute commands remotely by creating a new service on the remote system"; "Winexe installs a service on the remote system, executes the command, then uninstalls the service"
The data is held for ransom through encryption... operators continue to add new twists to their methods, from deleting backup systems simultaneously to encrypting the primary data set. | Ransomware is a type of malicious software designed to deny access to an information system or its resident data until a ransom is paid. The data is held for ransom through encryption...
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced as a source of illicit funds laundered through Garantex.
Ransomware family whose operators’ proceeds were laundered through the Garantex cryptocurrency exchange, per the article.
Ransomware variant explicitly cited as generating proceeds laundered through Garantex.
Ransomware that deletes shadow volumes to prevent recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.