Ransomware Group intelligence
Netwalker
InactiveTrack Netwalker with 26 published victims and 1 known leak locations in a single intelligence view.
Overview
Netwalker is tracked by Breach House as a ransomware group with 26 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion |
Top Activity Sectors (8)
Typical Attacks (18)
▼How Netwalker typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Netwalker.
-
T1047 Windows Management Instrumentation Execution
What they do: Netwalker can use WMI to delete Shadow Volumes.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Netwalker can use Windows API functions to inject the ransomware DLL.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
What that means: Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
T1027.009 Embedded Payloads Stealth
What they do: Netwalker's DLL has been embedded within the PowerShell script in hex format.
What that means: Adversaries may embed payloads within other files to conceal malicious content from defenses.
-
T1027.010 Command Obfuscation Stealth
What they do: Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Netwalker can detect and terminate active security software-related processes on infected systems.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1082 System Information Discovery Discovery
What they do: Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1518.001 Security Software Discovery Discovery
What they do: Netwalker can detect and terminate active security software-related processes on infected systems.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1486 Data Encrypted for Impact Impact
What they do: Netwalker can encrypt files on infected machines to extort victims.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Netwalker can terminate system processes and services, some of which relate to backup software.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Netwalker can delete the infected system's Shadow Volumes to prevent recovery.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (5)
▼Software Netwalker has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
netwalker.txt
Hi!
Your files are encrypted by Netwalker.
All encrypted files for this computer has extension: .eebf08
--
If for some reason you read this text before the encryption ended,
this can be understood by the fact that the computer slows down,
and your heart rate has increased due to the ability to turn it off,
then we recommend that you move away from the computer and accept that you have been compromised.
Rebooting/shutdown will cause you to lose files without the possibility of recovery.
--
Our encryption algorithms are very strong and your files are very well protected,
the only way to get your files back is to cooperate with us and get the decrypter program.
Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover.
For us this is just business and to prove to you our seriousness, we will decrypt you one file for free.
Just open our website, upload the encrypted file and get the decrypted file for free.
--
Steps to get access on our website:
1.Download and install tor-browser: https://torproject.org/
2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion
If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion
3.Put your personal code in the input form:
{code_eebf08:
[snip]}
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (26)
Search, filter and paginate the victim timeline for Netwalker. Showing 1–26 of 26.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Nygard International id544 View details | Canada | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | CSAT Solutions id535 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Enel Group id502 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KYB Corporation id488 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Wilmington Surgical Associates id490 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Equinix id477 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | K-Electric (electric utility supplier) id478 View details | Pakistan | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | Jands id468 View details | Australia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cygilant (threat detection cybersecurity company) id469 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Direccion Nacional de Migraciones (Argentina's official immigration agency) id465 View details | Argentina | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Entrust Energy id461 View details | United States | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | Center for Fertility and Gynecology (Los Angeles) id449 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Olympia House (Petaluma) id450 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Forsee Power id457 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Canadian Tire id459 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Alfanar id441 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Trinity Metro (Fort Worth transit agency) id432 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Lorien Health Services id401 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Columbia College of Chicago id399 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | University of San Francisco (UCSF) id393 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Michigan State University id379 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Network of Village of Weiz id361 View details | Austria | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Spectra Logic id362 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Northwest Territories Power Corporation id358 View details | Canada | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | Champaign-Urbana Public Health District id339 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Toll Group id323 View details | Australia | Services | — | |
|
No additional victim description available. |
|||||