Summary
First seen in 2012, NetWire is a remote access trojan (RAT).
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Netwire is currently spreading through spam email campaigns. These campaigns ask users to navigate to a URL disguised as a PDF invoice, this URL downloads a 7z file containing NetWire, which installs once decompressed.
Upon installation, Netwire will dynamically extract malicious code into its memory to avoid analysis. It will then add an autorun registry key, resulting in re-infection of the user's machine if it is removed. Netwire then connects to its command and control server before awaiting further commands, and has the following capabilities:
- Keylogging
- Browser password extraction
- Remote control capability
- Secondary payload installation
- User and system information collection
- Input device control
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm