NetWalker, also known as Mailto, is a human-operated ransomware family that emerged in 2019 and evolved into a ransomware-as-a-service operation. It is associated with double-extortion activity in which victim files are encrypted and stolen data is used to pressure payment through a leak site. NetWalker has been linked to attacks against high-value organizations worldwide, with notable concentration on education, healthcare, government, municipalities, law enforcement, emergency services, and enterprises in the United States. During the COVID-19 period, it continued targeting medical organizations and also heavily impacted universities and colleges.
NetWalker is notable for stealth-oriented execution and in-memory operation. Variants have been delivered through heavily obfuscated PowerShell loaders that decode and decrypt multiple layers before loading the ransomware DLL directly into memory. The malware has been observed executing filelessly and using reflective DLL injection into legitimate Windows processes for evasion. It can also use Windows API functions to inject its ransomware DLL, and process hollowing has been reported as part of its stealth tradecraft. NetWalker can terminate active security-related processes and has used registry-based persistence on Windows.
Operationally, NetWalker intrusions commonly involve post-compromise use of legitimate administrative and offensive tools. Reported tooling associated with NetWalker activity includes credential-dumping, remote administration, lateral movement, and Active Directory reconnaissance utilities. Stolen credentials have been used to expand access and deploy ransomware across victim environments, including network shares and administrative shares.
For encryption, NetWalker targets local drives, accessible network shares, and hidden administrative shares. Reported analyses indicate use of ChaCha for per-file encryption, with some observations of Salsa20 in certain cases. The malware also attempts to inhibit recovery by deleting Volume Shadow Copies. Embedded configuration data can include ransom-note content, file and directory exclusions, extension settings, and process kill lists.
NetWalker’s affiliate model recruited partners to conduct intrusions and spam-based distribution while operators maintained the ransomware codebase, payment infrastructure, and leak operations. Public reporting on the program described automated affiliate support features, unique builds, and restrictions against targeting Russia and other CIS countries. Law-enforcement action later disrupted parts of the operation, including seizure of infrastructure used for victim shaming and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
Two of the most common vulnerabilities exploited by actors using Netwalker are Pulse Secure VPN (CVE-2019-11510) and Telerik UI (CVE-2019-18935). | Indicators Associated with Netwalker Ransomware. As of June 2020, the FBI has received notifications of Netwalker ransomware attacks on U.S. and foreign government organizations, education entities, private companies, and health agencies by unidentified cyber actors.
In a trove of malicious files discovered while investigating a malware campaign from Netwalker, the researchers also found that the attacker also leveraged several vulnerabilities for privilege escalation. One of them is CVE-2020-0796, for which there is proof-of-concept exploit code released for local privilege escalation. It can also be exploited for remote code execution, but the code for this is not currently available to the public. | The demand is from Netwalker ransomware-as-a-service (RaaS) operators, a group that recently started to recruit skilled network intruders for their affiliate program.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Through multiple stages of obfuscated JavaScript, VBS scripts and/or PowerShell, the final Ursnif payload is written to the victim host.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
I notice that there are no MZ header to the binary file that are one technique to evade memory forensic tools or some quick check for injected executable to a process. | This also include the first part which is a obfuscated powershell that will serve as the loader of the malware.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
This includes process hollowing, in which the malware injects itself into a legitimate process such as explorer.exe and removes the original executable.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
AdFind can be used to discover computers, users, or groups with AD as a reconnaissance tool...
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
GetNetShares is often called to assist in locating hidden or administrative shares (admin$ / IPC$).
AdFind can query AD for computers, identify domain users and domain groups, extract subnet information from AD, and collect information about organizational units on domain trusts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
For example, the University of California, San Francisco paid $1.14 million last summer in exchange for a digital key needed to unlock files encrypted by the ransomware. | Encryption of shared accesses: if several users are logged in to the target computer, the ransomware will infect their mapped drives, as well as network resources where those users are logged in — shared accesses/NAS etc.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
Ransomware family heavily using COVID-themed lures and actively targeting healthcare and medical facilities.
A ransomware family whose affiliates appear to have collaborated with or moved into Conti after law-enforcement disruption. The leaks describe onboarding, operational friction, and use of TrickBot for distribution.
Ransomware family analyzed through recovered malware and related files, providing insight into operator TTPs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.