Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors netwalker

Description

NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group. Known victims: 26 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

NetWalker, an active ransomware group operated by 'CIRCUS SPIDER,' primarily targeted the healthcare sector globally from January 2020 to December 2020. Known for using tools like Mimikatz and legitimate software (LOLBINS) such as PSTools and AnyDesk, they were dismantled in January 2021 with significant assets seized by law enforcement.

Goals & Targeting

NetWalker's strategic focus on the healthcare sector aligns with its primary motivation of financial gain. Healthcare organizations are often seen as attractive targets due to the critical nature of their services and potentially higher ransoms. The group's global reach, despite concentrating efforts in the Asia Pacific region, underscores a broader strategy to maximize victims' vulnerability and willingness to pay. Their choice of targets reflects an understanding of sector-specific vulnerabilities and operational efficiency.

Enhanced Description

NetWalker is a sophisticated ransomware group that emerged in 2019 and became operational by early 2020. The group's main operator goes by the moniker 'CIRCUS SPIDER,' focusing on the healthcare sector, which they targeted globally despite their primary activity in the Asia Pacific region. NetWalker's operations involved deploying ransomware to encrypt victim systems and demand payments for decryption keys. Their toolset included Mimikatz for credential dumping and legitimate tools like PSTools and AnyDesk for lateral movement and persistence. This combination allowed them to maintain presence within networks and escalate privileges effectively. In January 2021, law enforcement successfully disrupted their operations, seizing financial assets, servers, and darknet infrastructure. Despite their operational hiatus, NetWalker's tactics highlight the evolving nature of ransomware threats, particularly targeting sectors with high recovery costs like healthcare.

Key Capabilities

  • Mimikatz for credential dumping
  • LOLBINS (PSTools, AnyDesk, TeamViewer, NLBrute)
  • Spear-phishing with malware-laced documents
  • Ransomware deployment and encryption

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Lateral Movement
Defense-Evasion

ATT&CK Techniques

T1003.001 - OS Credential Dumping: Windows Registry
T1564 - Use Alternate Authentication Mechanisms
T1055 - Process Injection
T1078.001 - Application Layer Protocol Proxy Usage

Software / Tooling

Mimikatz
PSTools
AnyDesk
TeamViewer
NLBrute

Campaigns & Victims

NetWalker's campaigns were characterized by their focus on healthcare, use of legitimate tools for infiltration, and methodical encryption processes. Their operational tempo was sustained until the 2021 takedown, which significantly disrupted their infrastructure. Past operations include multiple healthcare breaches, highlighting a pattern of targeting critical sectors for maximum impact.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • Presence of Mimikatz and LOLBIN tools in network processes
  • Encryption of files with NetWalker ransomware markers

Recommended Actions

  • Monitor network traffic for signs of Mimikatz or LOLBIN usage.
  • Enhance healthcare sector security measures, such as regular backups and segmentation.
  • Educate employees on identifying phishing attempts and suspicious emails.

Suggested Tags

Ransomware
Healthcare
Spear-Phishing
Law Enforcement Action

Confidence Assessment

High confidence in NetWalker's operational details due to law enforcement disclosure. Historical data may limit recent activity insights post-takedown, requiring updated intelligence for current threat assessments.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Healthcare
Spear-Phishing
Law Enforcement Action

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 31, 2020
Last Seen
Dec 12, 2020
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.