NetWalker is a ransomware group operated by CIRCUS SPIDER, primarily targeting the healthcare sector.
Analyst brief
NetWalker is a ransomware group operated by the threat actor "CIRCUS SPIDER", discovered in 2019. They primarily target the healthcare sector in the Asia Pacific region but can attack globally. Their TTPs include using Mimikatz for credential dumping and LOLBins such as PSTools, AnyDesk, TeamViewer, and NLBrute for lateral movement and persistence. Defenders should focus on restricting LOLBins usage, monitoring legitimate remote access tools for suspicious activity, and implementing detection rules for privilege escalation attempts within healthcare environments.
netwalker
crime
NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.
What is the name of the threat actor operating the NetWalker ransomware group?+
The NetWalker ransomware group is operated by a threat actor known as "CIRCUS SPIDER".
Which legitimate tools (LOLBins) does the NetWalker group use to penetrate networks?+
The NetWalker group uses legitimate tools (LOLBins) such as PSTools, AnyDesk, TeamViewer, and NLBrute, along with Mimikatz, to penetrate networks and escalate privileges.