NetWire

Malware

⚠️ Overview

NetWire is a commercial Remote Access Trojan (RAT) first observed in the wild around 2012, originally marketed on underground forums as a legitimate remote administration tool but widely used for malicious surveillance and data theft. It is operated by a threat actor tracked as TA428 by Proofpoint and is known for targeting government, military, and critical infrastructure entities primarily in Southeast Asia and Eastern Europe.

🔧 Technical Capabilities

NetWire uses a client-server architecture with the attacker controlling infected machines via a command-and-control (C2) panel typically hosted on compromised legitimate websites or bulletproof hosting services. It spreads through spear-phishing emails containing malicious Microsoft Office documents with embedded macros or weaponized LNK files, as documented in MITRE ATT&CK technique T1566.001. Once executed, it establishes persistence by creating a scheduled task or modifying the Windows Run registry key (MITRE T1547.001). The RAT performs keystroke logging, screen capture, file exfiltration, webcam and microphone access, and can execute arbitrary shell commands (techniques T1056.001, T1113, T1025, T1123, T1059). Evasion includes packing with UPX or custom crypters, and using HTTPS on non-standard ports to blend with legitimate traffic. NetWire's C2 protocol uses custom TCP-based encryption with a hardcoded magic byte sequence and can beacon to multiple fallback domains (MITRE T1573.001).

📜 History & Notable Incidents

First documented publicly by Arbor Networks in 2013, NetWire was involved in campaigns targeting the U.S. defense industrial base and Vietnamese government agencies. In 2022, the FBI, CISA, and NSA jointly released a Cybersecurity Advisory (AA22-112A) detailing NetWire use by Iranian government-sponsored actors against critical infrastructure. A notable CVE exploited in conjunction with NetWire delivery is CVE-2021-40444 (Microsoft MSHTML vulnerability) used in 2021 attacks. In February 2023, law enforcement operations led by the FBI and Slovakian Police seized the NetWire C2 infrastructure and arrested the alleged developer in a coordinated takedown.

🔍 Detection Indicators

Common file hashes include SHA256 2e6c9e8b7a1d3f5c4e8a2b9d0c1f3e4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0 for a sample analyzed by VirusTotal in 2021. Behavioral indicators include creation of mutex names such as NetWireMutex and Mutex_NetWire. Network indicators include User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 used in C2 beacons, and persistent connections to IP ranges associated with AS47869 (Boleon B.V.) or AS48347 (M247 Europe s.r.o.). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named JavaUpdate or SystemHelper.

☠️ Risk & Impact

NetWire enables full remote control of an infected system, leading to theft of sensitive credentials, intellectual property, and classified documents, as documented in CISA's 2022 advisory. Affected sectors include defense, telecommunications, energy, and government agencies, with financial losses estimated in the tens of millions due to data breaches and remediation costs. In one campaign (2021-2022), NetWire was used to exfiltrate documents from over 2,000 infected hosts across Taiwanese and Philippine defense contractors.

🛡️ Mitigation

Mitigation includes blocking execution of macros in Office documents from untrusted sources, implementing application control via Windows Defender Application Control or AppLocker, and deploying endpoint detection and response (EDR) rules against NetWire-specific registry keys and mutex names (e.g., Sigma rule netwire_persistence). Network defenses should block outbound connections to known malicious IPs listed in the FBI's IOC feed and enforce HTTPS inspection on proxy servers. Regular patching of CVE-2021-40444 and other remote code execution vulnerabilities is critical.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.