Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Netwalker

NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.
External information

Victims
 

26

First Discovered
victim

2020-01-31

Last Discovered
victim

2020-12-12

Avg Delay
between attack and claim

N/A

Infostealer
for victim with domain

N/A

View Victims on World Map


Known Locations (1)
Favicon Title Type Available Last Visit FQDN
favicon None No 2025-06-01 21:19:12 rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion

Target (Available)
Top 5 Activity Sectors
  • Healthcare and Public Health 5
  • Energy 4
  • Information Technology 4
  • Critical Manufacturing 4
  • Education Facilities 3
Top 5 Countries
  • US flag United States 13
  • CA flag Canada 3
  • AU flag Australia 2
  • AT flag Austria 1
  • AR flag Argentina 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
AdFind



Mimikatz

ProcDump
Cobalt Strike


PsExec



Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (0)

No TTPs available.


Negotiation Chats (0)

No negotiation chats available.


YARA Rules (1)

Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (26)
Logo
Nygard International Netwalker
Discovery Date: 2020-12-12
N/A
CA
Logo
CSAT Solutions Netwalker
Discovery Date: 2020-12-01
N/A
Logo
Enel Group Netwalker
Discovery Date: 2020-10-19
N/A
Logo
KYB Corporation Netwalker
Discovery Date: 2020-10-01
N/A
US
Logo
Equinix Netwalker
Discovery Date: 2020-09-07
N/A
US
Logo
Jands Netwalker
Discovery Date: 2020-09-01
N/A
AU
Logo
Entrust Energy Netwalker
Discovery Date: 2020-08-05
N/A
US
Logo
Olympia House (Petaluma) Netwalker
Discovery Date: 2020-08-01
N/A
US
Logo
Forsee Power Netwalker
Discovery Date: 2020-08-01
N/A
Logo
Canadian Tire Netwalker
Discovery Date: 2020-08-01
N/A
CA
Logo
Alfanar Netwalker
Discovery Date: 2020-07-09
N/A
Logo
Lorien Health Services Netwalker
Discovery Date: 2020-06-06
N/A
US
Logo
Columbia College of Chicago Netwalker
Discovery Date: 2020-06-03
N/A
US
Logo
Michigan State University Netwalker
Discovery Date: 2020-05-27
N/A
US
Logo
Network of Village of Weiz Netwalker
Discovery Date: 2020-05-01
N/A
AT
Logo
Spectra Logic Netwalker
Discovery Date: 2020-05-01
N/A
US
Logo
Toll Group Netwalker
Discovery Date: 2020-01-31
N/A
AU