Last seven days
- First activity
- Jul 21, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
NetWire is a remote access trojan (RAT) and credential-stealing malware family.
Profile source: Mallory opens in a new tabNETWIRE
NetWire is a remote access trojan (RAT) and credential-stealing malware family. The provided content associates it with process injection, keylogging-related behavior, command-and-control traffic, automated data collection, credential theft, persistence, and delivery through phishing and malware downloaders. NetWire has been observed stealing passwords from messaging and mail client applications and from web browsers including Internet Explorer, Opera, Yandex, and Chrome. It can automatically archive collected data, write collected data to files in a ./LOGS directory, copy itself to and execute from hidden folders, and inject code into processes including notepad.exe, svchost.exe, and vbc.exe. The content also notes registry-based persistence via HKCU\SOFTWARE\NetWire and an autorun entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, as well as macOS persistence through LaunchAgents. Execution and delivery vectors mentioned include spearphishing and email campaigns with malicious attachments or documents, PowerShell-based execution, and distribution by GuLoader. NetWire is described as cross-platform in at least one context, and Bahamut is specifically noted as using the publicly available cross-platform RAT NETWIRE alongside Revenge RAT. Threat actors and clusters explicitly associated with NetWire in the content include ModifiedElephant, which used NetWire and DarkComet against human rights activists, academics, journalists, and lawyers in India; TA2541, which has used NetWire in campaigns targeting aviation, aerospace, transportation, manufacturing, and defense organizations; Bahamut; and Nigerian BEC actors tracked as SilverTerrier. The content also notes behavioral overlap between NetWire and other commodity RATs such as WarZoneRAT, njRAT, and NanoCore due to similarities in injection, keylogging-related calls, and C2 traffic.
C2 tracking
Derp observations, rolling seven-day window
Samples
08769871094b040c53079550c0568a201b82667c9924d3b2bd8c4d791d0e34a2 9679eba64a2a1ae1befaf601c89a4f93f261b69b2a9ce43d5574410d38f3ada8 b33129d9282053a29bff59f9354314fc6bfd0b69078ac44bd05274815185c125 ebebecd071c4f37722c5abcf1c928b0ca03039b9e77d0b839602358d3a822ef7 edd2351fe3fe14eb4d8b7bf89369354951919bae11f97278d78da35727c0028f Reported operators
Currently, TA2541 prefers AsyncRAT, but other popular RATs include NetWire, WSH RAT and Parallax.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
"...identified at least 5 different malware families used as final payloadβall of them InfoStealer or RAT malware: ... Netwire"
Exploited software
MITRE ATT&CK
Reporting
A group of remote access trojans, among them WarZoneRAT, njrat, nanocore, and netwire, overlap on process injection, keylogging-related calls, and command-and-control traffic.
Infrastructure pivoting reveals the C2 IP (34.41.139.193) is shared with NetWire RAT, ClearFake, AsyncRAT, XWorm, Formbook, and Zeppelin ransomware.
19 netwire yes
With the release of v0.16, here are the different malware families that we cover. blister deprecated ghostpulse latrodectus lobshot lumma netwire redlinestealer remcos smokeloader stealc strelastealer xorddos
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.
"Most notably, the infrastructure utilized in this campaign overlapped with LAZIOK, NETWIRE and other malware targeting similar financial entities in these regions."
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.