U.S., Croatian, and Swiss authorities disrupted the long-running NetWire remote access trojan operation by seizing the worldwiredlabs[.]com sales domain, arresting alleged operator Mario Zanko in Croatia, and taking related infrastructure offline in Switzerland. The U.S. Department of Justice said the FBI investigated the malware distributor from 2020, including undercover purchases and analysis of NetWire’s builder tool, before obtaining the seizure warrant. NetWire had been marketed since 2012 as cross-platform remote administration software, but investigators said it was widely used for credential theft, keystroke logging, remote device control, fraud, data breaches, and intrusions affecting sectors including healthcare and banking.
Security research tied NetWire to multiple criminal campaigns and customized variants long before the takedown. Avast documented WiryJMPer, an obfuscated dropper disguised as cryptocurrency wallet software that decrypted and launched a NetWire payload while establishing persistence on infected Windows systems. VMware also analyzed a HYDSEVEN variant that altered NetWire’s command-and-control authentication and encryption, showing how threat actors adapted the malware for tailored operations. The malware had also targeted macOS users and appeared in broader phishing and exploit-driven campaigns, underscoring NetWire’s longevity and flexibility across platforms.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
On the same day, the FBI seized the worldwiredlabs domain, Croatian police arrested the alleged operator, and Swiss authorities seized a server hosting NetWire infrastructure as part of a coordinated international operation.
The FBI's Los Angeles field office began investigating the distributor behind World Wired Labs, including undercover purchases and use of the malware's builder tool.
In mid-November, VMware used ZMap to scan 52,128,684 hosts with port 443 open for HYDSEVEN's customized NetWire protocol but found no responsive command-and-control servers.
VMware Carbon Black Threat Analysis Unit reverse engineered HYDSEVEN's modified NetWire C2 authentication and encryption scheme and built a scanner to identify active servers.
Avast analyzed WiryJMPer, an obfuscated malware dropper disguised as an ABBC Coin wallet that decrypted and launched a NetWire payload and used cryptocurrency-themed decoys.
In a broad public attack, threat actors distributed NetWire by exploiting a zero-day vulnerability in Firefox.
Apple added detection for one NetWire variant to XProtect, expanding built-in macOS protections against the malware.
An August 2012 analysis found that the first Mac version of NetWire could steal passwords from Firefox, Opera, SeaMonkey, and Thunderbird.
NetWire began being sold commercially through the World Wired Labs website as a cross-platform remote access trojan marketed as remote control software.
NetWire was first discovered in 2012, marking the earliest identification of the RAT in the wild.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
www-index-hr.translate.goog
Open sourceintego.com
Open sourcetheregister.com
Open sourcejustice.gov
Open sourcekrebsonsecurity.com
Open sourceblogs.vmware.com
Open sourcedecoded.avast.io
Open sourceworldwiredlabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.