NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group. Known victims: 26 1 ransom note(s) on file
Objectives
Executive Summary
NetWalker, an active ransomware group operated by 'CIRCUS SPIDER,' primarily targeted the healthcare sector globally from January 2020 to December 2020. Known for using tools like Mimikatz and legitimate software (LOLBINS) such as PSTools and AnyDesk, they were dismantled in January 2021 with significant assets seized by law enforcement.
Goals & Targeting
NetWalker's strategic focus on the healthcare sector aligns with its primary motivation of financial gain. Healthcare organizations are often seen as attractive targets due to the critical nature of their services and potentially higher ransoms. The group's global reach, despite concentrating efforts in the Asia Pacific region, underscores a broader strategy to maximize victims' vulnerability and willingness to pay. Their choice of targets reflects an understanding of sector-specific vulnerabilities and operational efficiency.
Enhanced Description
NetWalker is a sophisticated ransomware group that emerged in 2019 and became operational by early 2020. The group's main operator goes by the moniker 'CIRCUS SPIDER,' focusing on the healthcare sector, which they targeted globally despite their primary activity in the Asia Pacific region. NetWalker's operations involved deploying ransomware to encrypt victim systems and demand payments for decryption keys. Their toolset included Mimikatz for credential dumping and legitimate tools like PSTools and AnyDesk for lateral movement and persistence. This combination allowed them to maintain presence within networks and escalate privileges effectively. In January 2021, law enforcement successfully disrupted their operations, seizing financial assets, servers, and darknet infrastructure. Despite their operational hiatus, NetWalker's tactics highlight the evolving nature of ransomware threats, particularly targeting sectors with high recovery costs like healthcare.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
NetWalker's campaigns were characterized by their focus on healthcare, use of legitimate tools for infiltration, and methodical encryption processes. Their operational tempo was sustained until the 2021 takedown, which significantly disrupted their infrastructure. Past operations include multiple healthcare breaches, highlighting a pattern of targeting critical sectors for maximum impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in NetWalker's operational details due to law enforcement disclosure. Historical data may limit recent activity insights post-takedown, requiring updated intelligence for current threat assessments.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics