NetWire Remote Access Trojan (RAT) is a malicious software application that permits malicious actors to remotely access victims’ computers. It’s frequently employed for surveillance activities, such as password theft and keylogging.
Recently, the FBI shut down a website selling malware and arrested its main suspect. Additionally, this RAT is being utilized in business email compromise scams.
It steals passwords and keystrokes
NetWire is one of the most well-known malware families, having first emerged in 2012. It has since been utilized by cybercriminals and state-sponsored threat actors to steal victim data and remotely control devices.
It was also used for other illicit activities, such as data exfiltration and infiltration – the latter of which proved more challenging for anti-virus software to prevent.
Malware is spread via phishing emails with click-bait file attachments that contain malicious macros. Once installed on an infected machine, this allows RATs to monitor keystrokes and mouse movements for its owner.
Once it has gained control of a victim’s computer, NetWire can collect user login data from web browsers and Microsoft Outlook profiles as well as log keystrokes. The threat then generates a log file containing all this collected information from the system before sending it to an online C2 server.
According to SentinelOne’s report, NetWire was a popular tool used by cybercriminals to spy on banks and healthcare businesses. It can also be used in ransomware attacks as it encrypts files and demands Bitcoin in exchange for decryption services.
Furthermore, the RAT can monitor email messages and download other payloads as it traverses the network. Furthermore, it has the capacity to capture screenshots, interact with a webcam, intercept audio files and manipulate metadata.
NetWire has also been known to target Android and Linux systems, making it a multi-platform threat. Typically, NetWire is installed through malicious Microsoft Office documents with macros that are then distributed via email as malicious attachments.
A US judge has granted a seizure warrant to seize the website selling the NetWire Remote Access Trojan (RAT), which is believed to be used for international money laundering and fraud. A Croatian national was arrested Tuesday on suspicion of running worldwiredlabs website which has been selling the malware for several years.
According to TechCrunch, the FBI conducted an investigation of NetWire and discovered it to be malicious software rather than a legitimate remote computer administration app. As such, authorities have seized both its domain and infrastructure.
It creates a log file
NetWire Remote Access Trojan (RAT) is a remote access trojan that can steal passwords, log keystrokes and control the victim’s computer remotely. Developed in 2012, it’s used by threat actors in numerous cybercrime campaigns. In addition to data theft, NetWire also installs malware on infected computers which allows it to perform POS attacks and conduct other malicious activities.
This RAT has been around for years and it’s one of the most popular on hacking forums. It has been employed in cybercrime efforts by various threat actors, such as Nigerian scammers and advanced persistent threats.
Spamhaus Botnet Threat Update – Q2 2020 lists NetWire as one of the 15 most active Real-Time Attack (RAT)s for 2019. Additionally, this RAT has been frequently targeted in Business Email Compromise (BEC) campaigns, where criminals send phishing emails with infected file attachments to employees.
Once activated, RAT software creates a log folder containing information gathered from the victim’s computer. This data includes keyboard and mouse activities, titles of what the victim is typing on, times, as well as IP address and network status.
NetWire employs a custom encryption algorithm to make data less susceptible to detection. Additionally, the registry keys, APIs, DLL names and other strings it writes into the log folder are obscured so static analysis tools have difficulty reading them.
Once it has collected all data necessary for processing, NetWire then attempts to establish a connection with its C2 server. To do this, it sends packets over the Internet with an IP address of 192[.]169[.]69[.]25 in order to send TCP connections via TCP protocol to its remote host.
SecureWorks researchers identified this particular version of the RAT in September 2016, collecting card data from a Point-of-Sale system. The attackers used a phishing campaign to infect employees with the malicious software.
It sends data to a C2 server
NetWire is a malicious program that executes various malicious tasks on infected systems. It has the capacity to steal user passwords and keystrokes, create a log file, and encrypt data before sending it off to a C2 server.
Netwire is a remote access Trojan that can infect Windows, Apple’s MacOS and Linux computers. It typically spreads via phishing campaigns as well as weaponized Microsoft documents, PDFs and archive files.
The malware employs multiple encryption layers and string obfuscation to make it difficult for researchers to decipher its operations. Furthermore, it utilizes a custom C2 binary protocol that is encrypted, making it even more resistant to hacking attempts.
NetWire sends a list of processes on an infected machine to a C2 server during its operation. The client requests this data via an pushed DF packet with the ASCII string “getprocesses.”
Once the server receives this message, it will reply with a CRLF-separated list of processes running on the infected computer. This list can then be parsed by the client and displayed to the attacker. Finally, the client sends back a zero-data ACK packet to conclude their conversation.
This process may be followed by a series of commands to further the malware’s malicious activities on an infected machine. It has the capability of taking control of the affected computer and performing other undesirable actions like installing an HTTP proxy or backdoor, as well as stealing credit card information.
Recent international law enforcement operations have disrupted NetWire, seizing its website and computer server. Croatian authorities arrested a man accused of running the site, while US and Swiss law enforcement agencies confiscated its computer server.
The RAT can be purchased on the dark net for anywhere from $40 to $140, with some versions going for as little as $10. It has been used in attacks against healthcare and banking industries alike.
Cyberattacks that utilize ransomware – a form of data encryption malware sent to victims as part of a command and control (C2) attack – also utilize this technique. Criminals then use the information obtained from victims to demand large sums of money in exchange for their data.
It obfuscates its activity
NetWire Remote Access Trojan is a multi-platform malware used by cybercriminals since 2012. It can take control of an infected machine and steal passwords, keystrokes and files while having remote access to C2 servers where it can execute commands.
The threat is typically spread via email phishing campaigns with malicious Microsoft Office documents. Once downloaded onto an infected system, it performs its malicious tasks.
Once downloaded and executed, the NetWire RAT encrypts data before sending it to a C2 server online. This includes keystroke information like time of keystrokes, titles typed in, as well as contents of Windows log folder (%AppData%Logs).
NetWire RAT conceals its activity by creating a suspended child process in which it modifies memory and thread context data, making it harder to analyze by automated security tools.
In addition to obfuscating its activity, the NetWire RAT employs anti-analysis techniques. These include using UPX-packed executables, detecting mouse moves and preventing execution in a sandbox. Furthermore, multiple data encryption layers, string obfuscation and a custom C2 binary protocol have all been utilized by this malware.
Obfuscation techniques are employed to make it difficult for researchers to detect a threat and stop it from running. It also permits attackers to inject code into seemingly innocent processes.
NetWire RAT is often distributed through phishing campaigns and social engineering tactics that target those with low IT literacy or no antivirus protection. It may be sent as an attachment to PDF, Word or IMG files via email.
NetWire Remote Access Trojan, like many other malware families, hides its activities through various means. It may inject itself into unpatched processes or create a file to mask its actions and send it off to a command-and-control server (C2 server).
Once installed on a machine, malware can begin stealing personal and financial data from that device. It could also be used for data exfiltration or installing backdoors.
Law enforcement authorities recently disrupted the operation of the NetWire RAT, seizing its website and arresting its distributor. It appears to have been run by a Croatian citizen named Mario Zanko who was arrested alongside its seizure on the same day as it was taken. He was selling licenses to use the NetWire RAT at prices ranging from $60-$140 each.


