Michigan State University said its network was breached by the NetWalker ransomware gang, which claimed to have stolen university data and threatened to publish it unless a ransom was paid within days. The attackers posted alleged proof of compromise, including directory listings, a passport scan, and financial documents, but the university did not disclose the intrusion timeline, operational disruption, or ransom demand. The incident reflected NetWalker’s broader shift toward larger enterprise and institutional victims in the US, Australia, and Western Europe.
Security researchers said NetWalker operators combined commodity remote-access tools such as TeamViewer, AnyDesk, and PsExec with credential theft, SMB-based lateral movement, and exploitation of known flaws including CVE-2020-0796 and weaknesses in outdated Tomcat or WebLogic servers or exposed RDP. Analyses of recovered samples showed a heavily obfuscated multi-stage PowerShell loader that injects the ransomware into explorer.exe, deletes shadow copies, dynamically resolves APIs to hinder analysis, and uses a layered cryptographic scheme based on X25519, ChaCha8, and HMAC-SHA256; Sophos also reported the gang used legitimate antivirus uninstallers to disable ESET, Trend Micro, and Microsoft protections and distributed unique DLL builds per victim.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CERT-AGID published a technical analysis concluding that NetWalker itself does not exfiltrate data or use network communication during encryption. The report described the malware's PowerShell-delivered DLL execution, encrypted JSON configuration, and cryptographic design based on X25519, ChaCha8, and HMAC-SHA256.
Michigan State University was listed by the Netwalker ransomware gang, which claimed to have stolen data and set a roughly six-day deadline for payment before public release. The attackers posted alleged proof including directory listings, a passport scan, and financial documents.
SophosLabs reported on a Netwalker ransomware campaign after recovering attacker tooling and at least 12 archived deployment packages. The research detailed use of legitimate remote-access tools, credential theft utilities, public exploit code, and enterprise-focused lateral movement methods, and noted IOCs were published on GitHub.
A reverse-engineering blog analyzed a Netwalker sample and described a three-stage obfuscated PowerShell loader that XOR-decrypted payloads, compiled C# via Add-Type, and injected the ransomware into explorer.exe. The analysis also documented API hashing, missing MZ headers, and anti-memory-forensics techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
en.wikipedia.org
Open sourcecert-agid.gov.it
Open sourcebleepingcomputer.com
Open sourcenews.sophos.com
Open sourcetccontre.blogspot.com
Open sourceen.wikipedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.