NETWIRE

S0198

Malware.View on attack.mitre.org

About this malware

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.

Techniques used45

Procedure examples45

TechniqueProcedure example
T1010
Application Window Discovery

NETWIRE can discover and close windows on controlled systems.

T1016
System Network Configuration Discovery

NETWIRE can collect the IP address of a compromised host.

T1027
Obfuscated Files or Information

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.

T1027.002
Software Packing

NETWIRE has used .NET packer tools to evade detection.

T1027.011
Fileless Storage

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.

T1036.001
Invalid Code Signature

The NETWIRE client has been signed by fake and invalid digital certificates.

T1036.005
Match Legitimate Resource Name or Location

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.

T1049
System Network Connections Discovery

NETWIRE can capture session logon details from a compromised host.

T1053.003
Cron

NETWIRE can use crontabs to establish persistence.

T1053.005
Scheduled Task

NETWIRE can create a scheduled task to establish persistence.

T1055
Process Injection

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.

T1055.012
Process Hollowing

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1056.001
Keylogging

NETWIRE can perform keylogging.

T1057
Process Discovery

NETWIRE can discover processes on compromised hosts.

T1059.001
PowerShell

The NETWIRE binary has been executed via PowerShell script.

View all 45 procedure examples

Groups that use it4

Campaigns0

None recorded.

References3

  1. FireEye APT33 Sept 2017 Open source
    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.
  2. FireEye APT33 Webinar Sept 2017 Open source
    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.
  3. McAfee Netwire Mar 2015 Open source
    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.