Skip to content

NETWIRE

NetWire is a commodity remote access trojan (RAT) active since at least 2014.

Profile source: Mallory opens in a new tab

NETWIRE

Family profile

NetWire is a commodity remote access trojan (RAT) active since at least 2014. It has been used by financially motivated and nation-state actors for covert surveillance, unauthorized remote administration, data theft, fraud, and network intrusion. NetWire supports keylogging, desktop screen capture, process discovery, collection of local IP-address information, and theft of credentials stored by web browsers. It can establish persistence through Windows Registry autostart entries or scheduled tasks, stores configuration data in the Windows Registry, and has used process hollowing to run within benign Microsoft executables. Its configuration is RC4-protected, while command-and-control communications can use AES encryption and HTTP. NetWire has been distributed in email-based Microsoft OneNote lure campaigns that require user interaction with embedded content. Windows is a prominent target platform; NetWire has also been represented as capable of infecting major desktop operating systems.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Aug 27, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • Google LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
RATicate

These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.

TA2541

According to the researcher’s observations, AsyncRAT, NetWire, WSH RAT, and Parallax appears to be the group’s top favorites being pushed most often in malicious messages.

DDGroup

To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: NetWire RAT

APT33

Between January and October 2019, each of the targets were sent spearphishing emails containing malicious links that, if opened, would have installed NetWire, a commercially available spyware.

Silver Spaniel

Of particular note is how these actors use a Remote Administration Tool (RAT) named NetWire (part of the NetWiredRC malware family). This RAT gives a remote attacker complete control over a Windows, Mac OS X, or Linux system through a simple graphical user interface.

HYDSEVEN

VMware Carbon Black Threat Analysis Unit (TAU) analyzed HYDSEVEN NetWire samples then implemented a scanner to discover active C2 servers on the Internet by emulating the customized C2 protocol.

ModifiedElephant

The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

WindShift

Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

Exploited software

Vulnerabilities linked to NETWIRE

4 CVEs

MITRE ATT&CK

NETWIRE in ATT&CK

79 distinct techniques

Techniques

79 techniques
T1027 Obfuscated Files or Information T1547.014 Active Setup T1547.001 Registry Run Keys / Startup Folder T1573.001 Symmetric Cryptography T1056.001 Keylogging T1059.001 PowerShell T1204.002 Malicious File T1566 Phishing T1204 User Execution T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer T1219 Remote Access Tools T1053.005 Scheduled Task T1555.003 Credentials from Web Browsers T1113 Screen Capture T1057 Process Discovery T1112 Modify Registry T1204.001 Malicious Link T1036.005 Match Legitimate Resource Name or Location T1055.012 Process Hollowing T1016 System Network Configuration Discovery T1543.001 Launch Agent T1573 Encrypted Channel T1560 Archive Collected Data T1059.003 Windows Command Shell T1027.011 Fileless Storage T1095 Non-Application Layer Protocol T1082 System Information Discovery T1059.005 Visual Basic T1119 Automated Collection T1564.001 Hidden Files and Directories T1071.001 Web Protocols T1555 Credentials from Password Stores T1074.001 Local Data Staging T1059 Command and Scripting Interpreter T1106 Native API T1027.002 Software Packing T1071 Application Layer Protocol T1036 Masquerading T1036.001 Invalid Code Signature T1566.002 Spearphishing Link T1049 System Network Connections Discovery T1053.003 Cron T1010 Application Window Discovery T1055 Process Injection T1560.003 Archive via Custom Method T1547.013 XDG Autostart Entries T1083 File and Directory Discovery T1547.015 Login Items T1102 Web Service T1059.004 Unix Shell T1056 Input Capture T1090 Proxy T1562 Impair Defenses T1047 Windows Management Instrumentation T1497 Virtualization/Sandbox Evasion T1033 System Owner/User Discovery T1568 Dynamic Resolution T1140 Deobfuscate/Decode Files or Information T1620 Reflective Code Loading T1553.002 Code Signing T1622 Debugger Evasion T1203 Exploitation for Client Execution T1056.002 GUI Input Capture T1539 Steal Web Session Cookie T1123 Audio Capture T1053 Scheduled Task/Job T1059.007 JavaScript T1001 Data Obfuscation T1564.004 NTFS File Attributes T1572 Protocol Tunneling T1565 Data Manipulation T1074 Data Staged T1555.005 Password Managers T1657 Financial Theft T1048 Exfiltration Over Alternative Protocol T1218.004 InstallUtil T1560.001 Archive via Utility T1090.001 Internal Proxy

Reporting

Research mentioning NETWIRE

May 25
Cyble Blog Historic

Invicta Stealer Spreads Via Fake GoDaddy Refund Invoices

Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.

Mar 1
Elastic Security Labs

Detect Credential Access with Elastic Security | Elastic Security Labs

Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.

Aug 18
Cyble Blog Historic

Cyble - BianLian: New Ransomware Variant On The Rise

BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.

Dec 1
Virusbulletin

Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor

Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.

Jul 1
Vmray

Cutting-off the Command-and-Control Infrastructure of CollectorGoomba | Threat Bulletin | VMRay

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.