NETWIRE is a publicly available commodity remote-access trojan first observed in 2012 and used by financially motivated and nation-state threat actors. It is described as cross-platform, with extensively documented Windows implementations. Its capabilities include remote control, keylogging, retrieval of passwords from messaging and email clients, and enumeration of running processes. NETWIRE can inject code into legitimate system processes and establish persistence through Windows Run entries and Active Setup.
NETWIRE supports TCP command-and-control communications and uses AES to encrypt communications with a key derived from a configured static password. Windows samples contain RC4-encrypted configuration data specifying command-and-control endpoints, persistence settings, installation locations, host identifiers, and keylogging parameters. A mutex prevents multiple instances from running simultaneously on an infected system.
Distribution includes malicious email attachments and links, macro-enabled Microsoft Word documents, and Microsoft OneNote lures requiring user interaction to execute embedded content. In REF2731 campaigns, tax-themed spam delivered the PARALLAX loader, which extracted and injected NETWIRE before the RAT established its own persistence. NETWIRE has been used by Bahamut for remote control and appears in OPERA1ER's commodity-malware arsenal; OPERA1ER targets banks, financial services, and telecommunications organizations, particularly in Africa. The REF2731 campaigns have not been attributed to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.
“Malware: Houdini, H-worm, QNodeJS, Adwind, Nanocore, Netwire, Metasploit Meterpreter, CobaltStrike beacon...”
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
According to the researcher’s observations, AsyncRAT, NetWire, WSH RAT, and Parallax appears to be the group’s top favorites being pushed most often in malicious messages.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: NetWire RAT
Between January and October 2019, each of the targets were sent spearphishing emails containing malicious links that, if opened, would have installed NetWire, a commercially available spyware.
45 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
262 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
164 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical comparison for misuse of the macOS defaults utility.
A remote access trojan associated here with process injection, keylogging-related calls, and command-and-control traffic.
NetWire RAT is identified as another malware family associated with the same shared IP infrastructure, with OTX linking it to ports 5202 and 8081 during Nov 2025-Feb 2026.
Mentioned as one of several RATs distributed via OneNote files, but not the specific malware unpacked in this case study.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.