Netwalker Ransomware

Description Summary

NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.

Threat Actor

'Circus Spider' RaaS; fileless (reflective PowerShell) loading; heavy healthcare targeting during COVID-19.

Technical Indicators

Encryption Extension
.<random 6-char>
Encryption Algorithm
Salsa20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
[extension]-Readme.txt
Targeted Industries
Healthcare, Education, Government
First Seen
August 2019 (as Mailto)
Last Seen
January 2021 (DOJ/international takedown)
Geographical Location
Worldwide (APAC focus)

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts