Netwalker Ransomware
First observed in late 2019, Netwalker (also known as Kazakavkovkiz or KoKo) is a fileless ransomware-as-a-service tool primarily targeted at enterprise targets in Western Europe and the USA. Whilst it was previously known as Mailto, the name was changed when Netwalker's creators began offering its services to affiliate users through a number of dark web sites.
Summary
First observed in late 2019, Netwalker (also known as Kazakavkovkiz or KoKo) is a fileless ransomware-as-a-service tool primarily targeted at enterprise targets in Western Europe and the USA. Whilst it was previously known as Mailto, the name was changed when Netwalker's creators began offering its services to affiliate users through a number of dark web sites.
Affected platforms
The following platforms are known to be affected:
Threat details
Unlike most MaaS ransomware, Netwalker's creators only offer it to affiliates with substantial network intrusion experience and prior access to target networks. Whilst this substantially reduces the number of potential affiliates Netwalker can be sold to, this seems to be a tactic to increase the monetary value of each individual attack, as well as limiting Netwalker's exposure to security agencies.
Netwalker is provided to affiliates as a heavily obfuscated and encrypted PowerShell script, which when executed uses reflective DLL injection to insert itself into a running explorer.exe process. It then attempts to exfiltrate data from a number of specified directories before deleting any Volume Shadow Copies. If successful, Netwalker begins to encrypt all non-system files using an unknown algorithm.
Information stolen by Netwalker is automatically posted to the MEGA file sharing site after an affiliate-specified countdown has elapsed.
For further information:
Update
Mailto is now being delivered in a number of new Covid-related spam campaigns against healthcare and government organisations,
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Indicators of compromise
Last edited: 29 June 2021 12:00 pm