NetWalker, also known as Mailto, is a human-operated ransomware family that emerged in 2019 and became prominent through double-extortion operations combining file encryption with theft and threatened publication of victim data. It evolved into a ransomware-as-a-service operation, enabling affiliates to deploy the malware against high-value organizations while operators maintained extortion infrastructure such as a Tor-based leak site and victim negotiation mechanisms. NetWalker has been associated with targeting organizations globally, with repeated reporting on impacts in education, healthcare, government, and other enterprise environments, including continued attacks on medical organizations during the COVID-19 period.
NetWalker is a Windows-focused ransomware family that has used heavily obfuscated PowerShell-based loaders and in-memory execution to reduce detection. Reported tradecraft includes multi-layer decoding and decryption of obfuscated payload stages, reflective DLL loading, DLL injection into legitimate processes, and process hollowing for stealth. The malware has also been observed modifying the Windows Registry for persistence and executing directly from memory. During execution, NetWalker can terminate security-related processes, delete shadow copies to inhibit recovery, and encrypt data on local drives, network shares, and administrative shares. Variants have used embedded configuration data to define ransom-note content, file exclusions, extensions, and process kill lists.
NetWalker intrusions have also involved extensive post-compromise activity by operators and affiliates using legitimate administrative and offensive tools. Reported tooling includes credential-dumping utilities, remote administration software, Active Directory reconnaissance tools, and remote execution utilities to expand access and deploy ransomware across victim environments. Stolen credentials have been used to facilitate lateral movement and remote execution. Delivery has included malicious email attachments, spam campaigns using topical lures such as COVID-19 themes, trojanized applications, and fileless execution chains. Public reporting has also linked NetWalker activity to broader enterprise intrusion patterns involving exposed remote services and affiliate-driven access operations.
The malware is notable for pairing mature intrusion tradecraft with extortion pressure. Victims that refused payment were threatened with public exposure of stolen data through NetWalker’s leak infrastructure, making restoration from backups alone insufficient to fully mitigate impact. Law-enforcement action in early 2021 disrupted parts of the operation and led to charges against an alleged operator, but NetWalker remains a significant example of the ransomware-as-a-service model and the broader shift toward data-theft-backed extortion in enterprise ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
Two of the most common vulnerabilities exploited by actors using Netwalker are Pulse Secure VPN (CVE-2019-11510) and Telerik UI (CVE-2019-18935). | Indicators Associated with Netwalker Ransomware. As of June 2020, the FBI has received notifications of Netwalker ransomware attacks on U.S. and foreign government organizations, education entities, private companies, and health agencies by unidentified cyber actors.
In a trove of malicious files discovered while investigating a malware campaign from Netwalker, the researchers also found that the attacker also leveraged several vulnerabilities for privilege escalation. One of them is CVE-2020-0796, for which there is proof-of-concept exploit code released for local privilege escalation. It can also be exploited for remote code execution, but the code for this is not currently available to the public. | The demand is from Netwalker ransomware-as-a-service (RaaS) operators, a group that recently started to recruit skilled network intruders for their affiliate program.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Through multiple stages of obfuscated JavaScript, VBS scripts and/or PowerShell, the final Ursnif payload is written to the victim host.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
I notice that there are no MZ header to the binary file that are one technique to evade memory forensic tools or some quick check for injected executable to a process. | This also include the first part which is a obfuscated powershell that will serve as the loader of the malware.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
This includes process hollowing, in which the malware injects itself into a legitimate process such as explorer.exe and removes the original executable.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
AdFind can be used to discover computers, users, or groups with AD as a reconnaissance tool...
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
GetNetShares is often called to assist in locating hidden or administrative shares (admin$ / IPC$).
AdFind can query AD for computers, identify domain users and domain groups, extract subnet information from AD, and collect information about organizational units on domain trusts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
For example, the University of California, San Francisco paid $1.14 million last summer in exchange for a digital key needed to unlock files encrypted by the ransomware. | Encryption of shared accesses: if several users are logged in to the target computer, the ransomware will infect their mapped drives, as well as network resources where those users are logged in — shared accesses/NAS etc.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
107 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as an example where blockchain analysis of ransom payments helped tie wallets to a specific operator and support prosecution.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
Ransomware family heavily using COVID-themed lures and actively targeting healthcare and medical facilities.
A ransomware family whose affiliates appear to have collaborated with or moved into Conti after law-enforcement disruption. The leaks describe onboarding, operational friction, and use of TrickBot for distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.