NetWalker is a financially motivated ransomware operation and malware family also known as Mailto and Koko. It emerged in 2019 and developed into a ransomware-as-a-service operation, recruiting affiliates to compromise enterprise networks and deploy ransomware in exchange for a share of ransom payments. Its victims included businesses, municipalities, hospitals, law enforcement agencies, emergency services, school districts, colleges, and universities. Healthcare organizations were specifically targeted during the COVID-19 pandemic. The operation affected hundreds of victims across at least 27 countries, with the majority located in the United States. NetWalker combined file encryption with theft of sensitive information and threats to publish stolen data. Its infrastructure included a public-facing victim-shaming site, Tor-based payment and negotiation services, an affiliate administration panel, and automated payouts. The affiliate program recruited network intruders and spam operators before increasingly emphasizing access to large enterprise networks. It prohibited attacks against Russia and other Commonwealth of Independent States countries. Initial access methods included insecure RDP configurations and exploitation of internet-facing applications, including Oracle WebLogic, Apache Tomcat, Pulse Secure VPN through CVE-2019-11510, and Telerik UI through CVE-2019-18935. Operators used TeamViewer, AnyDesk, custom PowerShell scripts, and legitimate security-product removal tools. They exploited CVE-2020-0796 for privilege escalation. The ransomware used Salsa20 encryption, could encrypt mapped drives and shared network storage, deleted shadow copies, injected code into a legitimate Windows process, and supported persistence through startup configuration. PowerShell-based payloads, obfuscation, and removal of security software supported defense evasion. U.S. and Bulgarian authorities seized NetWalker payment and leak infrastructure in January 2021. Subsequent prosecutions included Canadian affiliate Sébastien Vachon-Desjardins and Romanian affiliate Daniel Cristian Hulea, both of whom received 20-year prison sentences in the United States.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11510 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11539 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-1579 (Global Protect)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-19781 (Citrix)
In a trove of malicious files discovered while investigating a malware campaign from Netwalker, the researchers also found that the attacker also leveraged several vulnerabilities for privilege escalation. One of them is CVE-2020-0796, for which there is proof-of-concept exploit code released for local privilege escalation. It can also be exploited for remote code execution, but the code for this is not currently available to the public.
2 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
A ransomware operation whose affiliates may have integrated with Conti after law-enforcement disruption, using TrickBot distribution and Conti-provided tooling.
Ransomware operators mentioned as historical exploiters of CVE-2019-18935. The report does not connect them to the newly investigated attacks.
Ransomware operation whose proceeds were processed/laundered via Garantex per U.S. Treasury.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.