Researchers and antivirus vendors documented NetWire/Wirenet/NetWiredRC as a cross-platform backdoor affecting Linux and macOS, with capabilities including keylogging and theft of passwords from browsers and applications such as Firefox, Chrome, Chromium, Opera, Thunderbird, SeaMonkey, and Pidgin. Doctor Web reported that the malware copied itself into a user’s home directory and communicated with a command-and-control server at 212.7.208.65 using AES encryption, while malware-analysis records showed Linux ELF and macOS samples widely detected under multiple family names including Wirenet, NetWeirdRC, NetWiredRC, and Sabpab.
Further analysis tied the malware family to a custom encrypted TCP command-and-control protocol and showed it being used in campaigns linked to Silver Spaniel 419 scammers. Palo Alto Networks Unit 42 reverse engineered the protocol used by the NetWire RAT, finding that it used AES-256, attacker-selected static passwords, a seed exchange to derive separate session keys, and OFB mode for traffic encryption. The researchers released a decoder for NetWire 1.5c that can decrypt captured C2 traffic and reveal attacker-issued commands when responders have the infected client IP, malware port, and encryption password, giving incident responders a practical way to inspect NetWire activity during investigations.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
Red Canary published a technical analysis of the Linux variant of NetWire RAT, detailing ELF-based execution, persistence via XDG autostart .desktop files and crontabs, and observed artifacts such as self-copying to a hidden folder and creation of likely mutex and C2 configuration files. The report also attributed the sample to NetWire through VirusTotal detections, string overlap with prior macOS analysis, and alignment with NetWire documentation and release notes.
In November 2019, Proofpoint uncovered low-volume phishing campaigns delivering NetWire RAT with Bulgarian-language lures and geofencing that only served payloads to victims with Bulgarian IP addresses. The activity later expanded into additional related campaigns through 2020, using Word macros, certutil, and shared NetWire configuration elements including a common C2 domain and password.
Mandiant published analysis of a NETWIRE phishing campaign that used a VBS initial vector, PowerShell-based fileless execution, and process hollowing to deploy the malware. The report detailed credential-theft and surveillance capabilities and released host and network indicators including MD5 dac4ed7c1c56de7d74eb238c566637aa and multiple C2 endpoints.
Palo Alto Networks Unit 42 published a report on July 22 about the evolution of Silver Spaniel 419 scammers, noting their use of the NetWire remote administration tool in operations.
CIRCL published technical report TR-23 analyzing NetWiredRC malware, which Palo Alto later cited as documenting a complete list of NetWire commands.
On December 7, 2012, two more NetWiredRC-related samples—one Linux ELF and one macOS binary—were analyzed, with numerous antivirus vendors classifying them as backdoors or trojans under WireNet/NetWeird/NetWiredRC names.
In November and December 2012, malware samples associated with WireNet/NetWeird/NetWiredRC were analyzed and detected by multiple antivirus engines, showing active recognition of Linux and macOS variants in the wild.
On August 22, 2012, Doctor Web reported Mac.BackDoor.Wirenet.1, describing it as a cross-platform backdoor for Linux and Mac OS X that steals passwords and logs keystrokes while communicating with a C2 server over AES-encrypted traffic.
Unit 42 reverse engineered NetWire's encrypted TCP protocol and released a decoder tool that can decrypt captured NetWire traffic and reveal attacker-issued commands for incident responders.
McAfee published a report describing NetWire RAT as the malware behind recent targeted attacks, adding campaign-focused reporting on the threat's operational use. This represents a new documented use of NetWire beyond the earlier sample analyses and technical reporting already in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
12 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourceredcanary.com
Open sourcemandiant.com
Open sourceattack.mitre.org
Open sourcecontagiodump.blogspot.com
Open sourcenews.drweb.com
Open sourcebrighttalk.com
Open sourcesecuringtomorrow.mcafee.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.