Skip to content

Netwalker

NetWalker is a ransomware family and ransomware-as-a-service (RaaS) operation.

Profile source: Mallory opens in a new tab

Netwalker

Family profile

NetWalker is a ransomware family and ransomware-as-a-service (RaaS) operation. The provided content states that it encrypts files on infected machines to extort victims, deletes Shadow Volumes to inhibit recovery, and can use WMI to delete shadow copies. It can detect and terminate active security software-related processes on infected systems, indicating defense-evasion behavior. NetWalker has been described as written in PowerShell, executed directly in memory to avoid detection, with its DLL embedded in the PowerShell script in hex format; related reporting also notes multiple layers of PowerShell obfuscation including Base64, hexadecimal encoding, XOR encryption, and obfuscated functions and variables. The content also references a registry artifact in the form of an added entry under HKEY_CURRENT_USER\SOFTWARE\{8 random characters}. Infection and access vectors mentioned in the content include coronavirus-themed phishing lures, including attacks against Spanish hospitals, .vbs attachments in COVID-19-themed emails, exploitation of Telerik UI for ASP.NET AJAX vulnerability CVE-2019-18935, and compromises of misconfigured IIS-based applications followed by use of tools such as Mimikatz and PsExec before ransomware deployment. NetWalker is associated in the content with the threat actor Circus Spider, which is described as generally targeting hospitals in the U.S. and Spain. Additional ecosystem references note that UNC2628 was believed to partner with multiple RaaS services including NetWalker, and that law enforcement seized NetWalker data leak and payment sites in January 2021, with other reporting in the content referring to the arrest of an affiliate and the program's subsequent demise. The content also notes that Garantex received cryptocurrency proceeds from Russia-linked ransomware attacks including NetWalker.

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Credential Theft

  • Mimikatz
  • ProcDump

Discovery Enum

  • AdFind

LOLBAS

  • PsExec

Offsec

  • Cobalt Strike

Reported operators

Threat actors

3 named in public reporting
UNC2628

UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.

Wazawaka

In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.

Exploited software

Vulnerabilities linked to Netwalker

1 CVEs

MITRE ATT&CK

Netwalker in ATT&CK

27 distinct techniques

Reporting

Research mentioning Netwalker

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.