NetWire RAT is a long-running commodity remote access trojan used by criminal operators and also observed in targeted intrusion and cyberespionage activity. It supports remote control of compromised systems over a custom TCP-based command-and-control protocol and uses AES-encrypted communications. Network traffic is characterized by packets that begin with a length field followed by a one-byte command and associated data, and the initial key exchange includes material used to derive the AES session key.
NetWire is commonly delivered as a second-stage payload by malware loaders and downloaders such as GuLoader and DBatLoader, and it has also appeared in phishing and spearphishing campaigns using macro-enabled documents, JavaScript droppers, archive and disk-image containers, and exploit-driven delivery including CVE-2017-11882 and exploit kits. Campaigns have used themes such as travel reservations, tax documents, job-related lures, and topical social-engineering content. It has also been deployed in attacks abusing WinRAR ACE path traversal vulnerability CVE-2018-20250 to achieve persistence and execute on reboot.
The malware has been associated with a broad range of threat activity, including campaigns linked to groups such as SilverTerrier, Hydrojiin, and financially motivated intrusion clusters overlapping with OPERA1ER and Bluebottle. Victimology spans financial services, businesses, medical organizations, educational institutions, military targets, and banks in Africa, reflecting both opportunistic and targeted use.
NetWire primarily targets Windows and has also been described as available for macOS and Linux. As a remote access trojan, it is used for post-compromise control of infected hosts and is frequently paired with broader intrusion activity involving credential theft, persistence, lateral movement, and follow-on tooling. Its prevalence as a commodity payload and its encrypted non-HTTP/S communications have made it a recurring component of both mass-malware distribution and hands-on-keyboard intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NetWire communicates with custom protocols over TCP and communication is encrypted with AES encryption. Each packet begins with a length of data followed by one byte for the command and then followed by data.
NetWire communicates with custom protocols over TCP and communication is encrypted with AES encryption. Each packet begins with a length of data followed by one byte for the command and then followed by data.
Aggah specifically has been seen using paste.ee to host njRAT, NetWire RAT, RevengeRAT, Agent Tesla.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
This installed version of AsyncRAT connects to its C2 servers located at “znets[.]ddns[.]net” and “dnets[.]ddns[.]net”.
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: HTTP T1071.001 JSON-over-HTTP POST to C2 gate
Almost one-third of prevalent malware families we recently analyzed support communication over non-HTTP/S protocols.
Downloads the file stored on Google Drive/OneDrive and decrypts it.
AsyncRAT provides remote access to attackers and allows them to remotely monitor and control a compromised machine through a secure encrypted connection.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used in multiple campaigns and APT activity. Often delivered as a second-stage payload or via exploit kits, and uses custom AES-encrypted TCP communications.
A remote access trojan delivered as a final payload by DBatLoader.
Mentioned as an example of malware that GuLoader can download.
A remote access Trojan capable of stealing passwords, keylogging, and providing remote control capabilities on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.