Netwalker

S0457

Malware.View on attack.mitre.org

About this malware

Netwalker is fileless ransomware written in PowerShell and executed directly in memory.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1027.009
Embedded Payloads

Netwalker's DLL has been embedded within the PowerShell script in hex format.

T1027.010
Command Obfuscation

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1047
Windows Management Instrumentation

Netwalker can use WMI to delete Shadow Volumes.

T1055.001
Dynamic-link Library Injection

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1059.001
PowerShell

Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.

T1059.003
Windows Command Shell

Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload.

T1082
System Information Discovery

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.

T1105
Ingress Tool Transfer

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1106
Native API

Netwalker can use Windows API functions to inject the ransomware DLL.

T1112
Modify Registry

Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.

T1140
Deobfuscate/Decode Files or Information

Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.

T1486
Data Encrypted for Impact

Netwalker can encrypt files on infected machines to extort victims.

T1489
Service Stop

Netwalker can terminate system processes and services, some of which relate to backup software.

T1490
Inhibit System Recovery

Netwalker can delete the infected system's Shadow Volumes to prevent recovery.

T1518.001
Security Software Discovery

Netwalker can detect and terminate active security software-related processes on infected systems.

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. TrendMicro Netwalker May 2020 Open source
    Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.