NetWalker, also tracked as Mailto and Koko, emerged in 2019 as a ransomware family that increasingly targeted enterprise networks and later matured into a ransomware-as-a-service (RaaS) operation. Early campaigns used spam lures, including COVID-19-themed emails carrying a Visual Basic Script dropper, while other intrusions were linked to exposed RDP, vulnerable Pulse Secure VPN (CVE-2019-11510), Telerik UI (CVE-2019-18935), Oracle WebLogic, and Apache Tomcat. The malware encrypted Windows systems, deleted shadow copies, appended victim-specific extensions such as .mailto[{mail1}].{id}, and dropped ransom notes like {ID}-Readme.txt; over time, operators shifted from email-based negotiations to Tor payment portals and leak sites.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
On January 27, 2021, U.S. and Bulgarian authorities seized NetWalker dark websites, including Tor payment and leak sites, as part of a joint investigation. The same day, the U.S. Department of Justice charged Sebastien Vachon-Desjardins.
In January 2021, police seized 719.99591411 BTC from Sebastien Vachon-Desjardins's Bitcoin wallet, along with Monero, cash, deposit-box funds, devices, and roughly 20 TB of data. The seizures were tied to the NetWalker investigation.
A researcher shared a NetWalker ransom note tied to Enel Group with BleepingComputer. The note included a screenshot link allegedly showing stolen data.
In October 2020, NetWalker reportedly hit Enel Group and demanded $14 million for a decryptor and a promise not to release stolen data. The attackers claimed to have taken several terabytes of company data.
Enel Group had previously been attacked in early June 2020 by Snake, also known as EKANS. The company detected the attack on its internal network before the malware could spread.
An actor using the alias Bugatti advertised NetWalker on underground forums to recruit affiliates under a ransomware-as-a-service model. The offering included a Tor-based administration panel and automated service.
A March 18 report cited by the source said NetWalker operators claimed hospitals and medical facilities were not their intended targets. The statement came amid concern over attacks during the COVID-19 crisis.
A malicious VBS attachment named CORONAVIRUS_COVID-19.vbs used to distribute NetWalker was first analyzed on VirusTotal. The lure was part of a COVID-19-themed spam campaign.
NetWalker, also known as Mailto or Koko, began operating in early September 2019. One sample referenced in the source had a compilation date of September 1, 2019.
Researchers first spotted the Mailto/NetWalker ransomware in August 2019 via ID Ransomware. This early tracking helped establish the family before later enterprise-focused incidents were reported.
Sebastien Vachon-Desjardins was sentenced in Canada to 6 years and 8 months in prison for his role in NetWalker ransomware attacks after pleading guilty to offenses tied to 17 Canadian victims. The court said he played a dominant role despite cooperating with authorities.
A Canadian NetWalker affiliate, Sebastien Vachon-Desjardins, victimized 17 Canadian entities and others worldwide by breaching networks, stealing data, demanding ransom, and distributing stolen data when victims did not pay. The court said this activity occurred between May 2020 and January 2021.
The new reference identifies the University of California San Francisco as a NetWalker victim during the period when the ransomware was heavily targeting U.S. educational institutions. This adds a specific victim disclosure not present in the existing timeline.
NetWalker later added Enel Group to its leak site and published screenshots of unencrypted files as proof of compromise. The gang said it had stolen about 5 TB of data and threatened to publish part of it within a week.
By August 1, 2020, NetWalker had generated about $25 million for its operators since March 2020. The figure illustrated the scale and profitability of the ransomware operation.
A May 2020 update stated that NetWalker shifted fully toward targeting large enterprises and sought to avoid Russian and CIS targets. This reflected a strategic change in victim selection.
A May 12, 2020 update said NetWalker added automatic victim data publication, process unlocking via the Restart Manager API, and PowerShell-based builds. The changes reflected an expansion of the malware's capabilities.
By March 2020, NetWalker ransom notes were directing victims to Tor-based payment portals instead of relying only on email contact. This marked an operational change in how the ransomware handled extortion.
Australian company Toll Group disclosed that its network had been attacked by Mailto ransomware. The incident contributed to researchers concluding that the ransomware was targeting enterprise environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceincibe-cert.es
Open sourcebleepingcomputer.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.