NetWire is a commodity remote-access trojan active since at least 2014 and used by financially motivated and nation-state actors. Elastic Security Labs reported increased telemetry prevalence in the second half of 2022 and released tooling to extract the malware's dynamically embedded configuration, enabling defenders to identify its command-and-control (C2) infrastructure and host-specific settings.
The extractor decrypts NetWire’s RC4-protected configuration to recover C2 IP addresses and domains, installation and keylogger-log paths, host identifiers, mutexes, persistence settings, and communications-encryption parameters. NetWire can establish persistence through Registry Run Keys/Startup Folder mechanisms (MITRE ATT&CK T1547.014); defenders should hunt for its recovered indicators and persistence artifacts and deploy YARA detections covering NetWire mutexes, keylogging strings, and related binary artifacts.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs observed increased NETWIRE prevalence in its telemetry during the second half of 2022.
Jean-Philippe Teissier authored the win_netwire_w0 memory-focused YARA rule for NetWiredRC, including the LmddnIkX mutex and keylogging-related strings.
Kevin Breen authored the win_netwire_w1 YARA rule, classifying NetWire as a remote-access trojan and matching artifacts including key-state strings and SQLite-related strings.
NETWIRE was active by at least 2014 and was used by both financially motivated and nation-state threat actors.
Felix Bilstein's yara-signator-generated win_netwire_auto rule was dated 2026-05-04. The rule detects win.netwire by requiring seven defined sequences and a file size below 416,768 bytes.
Elastic Security Labs developed an extractor that decrypts NETWIRE's RC4-protected configuration and recovers C2 infrastructure, persistence settings, host identifiers, installation paths, mutexes, and C2 encryption parameters. The research also supplied NETWIRE YARA rules and C2 IP and domain indicators derived from recently collected samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 66 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.