Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Netwalker

NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.
External information

Victims
26
 
First Discovered
2020-01-31
victim
Last Discovered
2020-12-12
victim
Inactive Since
5yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
N/A
victims with domain

View Victims on World Map

View group statistics


Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon None No 2025-06-01 21:19:12 rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion

Target (Available)
Top 5 Activity Sectors
  • Healthcare and Public Health 5
  • Energy 4
  • Information Technology 4
  • Critical Manufacturing 4
  • Education Facilities 3
Top 5 Countries
  • US flag United States 13
  • CA flag Canada 3
  • AU flag Australia 2
  • AT flag Austria 1
  • AR flag Argentina 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
AdFind



Mimikatz

ProcDump
Cobalt Strike


PsExec



Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (0)

No TTPs available.


Negotiation Chats (0)

No negotiation chats available.


YARA Rules (1)

Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (26)
Logo
Discovered: 2020-12-12
No description available
Logo
Discovered: 2020-12-01
No description available
Logo
Discovered: 2020-10-19
No description available
Logo
Discovered: 2020-10-01
No description available
Logo
Discovered: 2020-10-01
No description available
Logo
Discovered: 2020-09-07
No description available
Logo
Discovered: 2020-09-07
No description available
Logo
Discovered: 2020-09-01
No description available
Logo
Discovered: 2020-09-01
No description available
Logo
Discovered: 2020-08-05
No description available
Logo
Discovered: 2020-08-01
No description available
Logo
Discovered: 2020-08-01
No description available
Logo
Discovered: 2020-08-01
No description available
Logo
Discovered: 2020-08-01
No description available
Logo
Discovered: 2020-07-09
No description available
Logo
Discovered: 2020-07-01
No description available
Logo
Discovered: 2020-06-06
No description available
Logo
Discovered: 2020-06-03
No description available
Logo
Discovered: 2020-06-01
No description available
Logo
Discovered: 2020-05-27
No description available
Logo
Discovered: 2020-05-01
No description available
Logo
Discovered: 2020-05-01
No description available
Logo
Discovered: 2020-04-30
No description available
Logo
Discovered: 2020-03-10
No description available
Logo
Discovered: 2020-01-31
No description available