NetTraveler, also known as Travnet, is a long-running Windows espionage malware family used in targeted intrusions since at least the mid-2000s. It is primarily associated with China-linked cyber-espionage activity and has been used against government institutions, embassies, military contractors, research organizations, political activists, and private-sector entities across dozens of countries, with notable targeting in Mongolia, Russia, India, Kazakhstan, Belarus, and neighboring regions.
NetTraveler is designed chiefly for document theft and basic host surveillance. Reported collection priorities include common office and document formats such as DOC, XLS, PPT, RTF, and PDF, with some configurations also targeting engineering and design-related file types. The malware also includes keylogging functionality and records window names or foreground application context alongside captured keystrokes, improving the intelligence value of stolen input.
Observed delivery has centered on spearphishing campaigns using weaponized Microsoft Office documents, including exploits for CVE-2012-0158 and CVE-2010-3333. In later activity, operators also used links to compressed executable payloads and RAR self-extracting archives. Campaign lures were typically tailored to victim interests and regional geopolitical themes, including military, diplomatic, energy, and policy subjects.
Operationally, NetTraveler has been observed using DLL sideloading with legitimate signed executables to load malicious components and encrypted configuration data. Reporting also links the family to steganographic tradecraft in some discussions of broader malware ecosystems, though its best-established role is as a targeted espionage implant for surveillance and document exfiltration. Infrastructure and code overlaps have tied NetTraveler to other China-linked tooling and campaigns, including PlugX, Cmstar, and ZeroT, suggesting either shared operators or shared malware supply within overlapping espionage clusters.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The primary attack method consists of spear-phishing emails carrying malicious documents that exploit two remote code execution vulnerabilities that affect Microsoft Office, namely CVE-2012-0158 and CVE-2010-3333, in order to install the malware. | Researchers from antivirus vendor Kaspersky Lab named the campaign NetTraveler, after a string found in the main data stealing malware associated with the attacks. NetTraveler, also known as Travnet, is designed to steal documents, primarily DOC, XLS, PPT, RTF and PDF, and to perform basic computer surveillance.
Researchers from antivirus vendor Kaspersky Lab named the campaign NetTraveler, after a string found in the main data stealing malware associated with the attacks. NetTraveler, also known as Travnet, is designed to steal documents, primarily DOC, XLS, PPT, RTF and PDF, and to perform basic computer surveillance. | The primary attack method consists of spear-phishing emails carrying malicious documents that exploit two remote code execution vulnerabilities that affect Microsoft Office, namely CVE-2012-0158 and CVE-2010-3333, in order to install the malware.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158, or URLs linking to RAR-compressed executables... added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.
The first file is a dropper used to register a malicious DLL (NetTraveler trojan) as a service... A new service called “FastUserSwitchingCompatibility” is created using CreateServiceA API function... A new key called “Parameters” is created... This will be used to register a malicious DLL as a service.
the attacker’s purpose is to steal “explorer.exe” process’ token by calling OpenProcessToken... and then it uses ImpersonateLoggedOnUser function to impersonate the security context of a user.
The first file is a dropper used to register a malicious DLL (NetTraveler trojan) as a service... A new service called “FastUserSwitchingCompatibility” is created using CreateServiceA API function... A new key called “Parameters” is created... This will be used to register a malicious DLL as a service.
A new service called “FastUserSwitchingCompatibility” is created... which tries to impersonate the legitimate service... Attackers will try to impersonate/use legitimate system binaries or libraries on the host to hide malicious activity.
If all methods fail, the infection will stop and the following operations are performed (self-deleting malware)... registry keys are deleted... The following files are deleted as well...
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The main purpose of the trojan is to gather information about the environment... the list of processes... A list of processes is retrieved using Process32First and Process32Next APIs...
The main purpose of the trojan is to gather information about the environment such as user name, host name, IP address of the host, Windows OS version, different configurations of the CPU, information about memory consumption...
The file will enumerate all files and directories from the “C:\” drive... all information described will be stored in a new file called “C:\Windows\SysWOW64\enumfs.ini”... The operation applied to “C:\” drive is recursive...
NetTraveler, also known as Travnet, is designed to steal documents, primarily DOC, XLS, PPT, RTF and PDF, and to perform basic computer surveillance. However, some configurations target extended lists of files, including those with extensions like CDR... or DWG, DXF, CDW and DWF...
The malicious process is interested in .doc, .docx, .xls, .xlsx, .txt, .rtf, .pdf files on disk and also on USB drives...
The malicious process is interested in .doc, .docx, .xls, .xlsx, .txt, .rtf, .pdf files... also on... network shares in order to exfiltrate them.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The data is compressed using a custom Lempel-Ziv-based algorithm and encoded with a modified Base64 algorithm before it will be exfiltrated to the Command and Control server.
The user agent used in the network communications is always set to “Mozilla/4.0 (compatible; MSIE 6.0)”... The encoded data is exfiltrated via a GET request to vipmailru[.]com (C2 server).
the attacker verifies if he’s able to connect to the same URL using the proxy settings he found in the registry... the malicious process modifies the config_t.dat file by setting UP=1... and then PS (proxy server), PP (proxy port), PU (proxy user), PW (proxy password) are set according to the settings found.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Семейство вредоносного ПО, упомянутое как использующее стеганографию для сокрытия данных или коммуникаций.
Malware containing a keylogger.
Backdoor family referenced via C2 infrastructure overlap/WHOIS linkage in the report’s pivoting analysis.
Named malware/tool mentioned in attribution analysis as part of broader comparison/background.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.