NetWalker, also known as Mailto, is a Windows ransomware family that encrypts files on compromised systems to extort victims. Its criminal operation has recruited affiliates to deploy the ransomware. Healthcare organizations and medical facilities have been targeted, including Spanish hospitals attacked using coronavirus-themed phishing lures.
NetWalker uses PowerShell-based execution chains that decode and decrypt multiple layers of obfuscation before loading a ransomware DLL into memory. The DLL can be reflectively injected into a legitimate running process, reducing reliance on disk-based payload execution and helping evade detection. NetWalker payloads have also been protected with the CryptOne crypter. Operators have used PsExec to copy ransomware payloads across accessible systems within compromised networks, supporting lateral deployment. Initial compromises associated with NetWalker operators have included exploitation of CVE-2019-18935, a remote-code-execution vulnerability in Telerik UI for ASP.NET AJAX. In January 2021, law enforcement seized NetWalker infrastructure and charged a Canadian operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the incidents we investigated, the threat actor exploited the vulnerability (designated CVE-2019-18935) to deliver a Cobalt Strike beacon (in the form of a DLL payload) to disk.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
In a trove of malicious files discovered while investigating a malware campaign from Netwalker, the researchers also found that the attacker also leveraged several vulnerabilities for privilege escalation. One of them is CVE-2020-0796, for which there is proof-of-concept exploit code released for local privilege escalation. It can also be exploited for remote code execution, but the code for this is not currently available to the public. | The demand is from Netwalker ransomware-as-a-service (RaaS) operators, a group that recently started to recruit skilled network intruders for their affiliate program.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
I notice that there are no MZ header to the binary file that are one technique to evade memory forensic tools or some quick check for injected executable to a process. | This also include the first part which is a obfuscated powershell that will serve as the loader of the malware.
This includes process hollowing, in which the malware injects itself into a legitimate process such as explorer.exe and removes the original executable.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
For example, the University of California, San Francisco paid $1.14 million last summer in exchange for a digital key needed to unlock files encrypted by the ransomware. | Encryption of shared accesses: if several users are logged in to the target computer, the ransomware will infect their mapped drives, as well as network resources where those users are logged in — shared accesses/NAS etc.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
114 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as an example where blockchain analysis of ransom payments helped tie wallets to a specific operator and support prosecution.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
Ransomware family heavily using COVID-themed lures and actively targeting healthcare and medical facilities.
A ransomware family whose affiliates appear to have collaborated with or moved into Conti after law-enforcement disruption. The leaks describe onboarding, operational friction, and use of TrickBot for distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.