LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0198: NETWIRE

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.[1][2][3]

EnterpriseS0198MalwareObject v1.6Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

NETWIRE matters because it is a publicly available remote administration tool with Windows, Linux, and macOS relevance, and ATT&CK records use by multiple criminal and APT groups. For leaders, the decision point is not whether the tool name appears in an alert, but whether endpoint, identity, and network defenses can recognize the behaviors commonly associated with this RAT: persistence, command execution, discovery, credential collection through keylogging, staging, obfuscation, and web-based command-and-control.

Executive priority

Treat NETWIRE as a resilience and readiness test case for commodity RAT defense across a mixed operating-system estate. Its public availability and relationship to multiple groups make it useful for validating whether controls depend too heavily on known signatures. Security leaders should ask whether SOC coverage includes cross-platform endpoint telemetry, command-line visibility, scheduled task and cron monitoring, suspicious process injection indicators, keylogging-related detections, and web-protocol C2 review. This also supports audit and incident-readiness evidence: teams should be able to show how they detect and respond to remote access tooling even when ATT&CK provides no object-specific detection guidance.

Technical view

ATT&CK does not provide a NETWIRE-specific detection field, so defenders should validate coverage through its related techniques. On Windows, prioritize visibility into PowerShell, cmd, scheduled tasks, invalid code signatures, process injection and process hollowing, local staging, and suspicious web-protocol communications. On Linux and macOS, validate Unix shell execution, cron persistence, process and network discovery, application window discovery where applicable, local staging, fileless or nonstandard storage locations, packing or obfuscation indicators, and web-protocol C2 patterns. IR teams should correlate discovery commands, persistence artifacts, credential-access behavior such as keylogging, and outbound communications rather than relying on the malware family name alone.

Likely telemetry

  • Endpoint process creation and command-line telemetry across Windows, Linux, and macOS
  • PowerShell, Windows command shell, Unix shell, and Visual Basic execution records where applicable
  • Windows scheduled task creation or modification logs
  • Cron entry creation or modification on Linux and macOS
  • Endpoint memory or EDR telemetry for process injection and process hollowing indicators

Detection direction

  • Build detections around behavior clusters rather than the NETWIRE name: execution plus persistence, discovery plus outbound web traffic, or keylogging plus local staging should raise priority.
  • Tune scheduled task and cron alerts to distinguish approved administration from newly created or unusual recurring execution paths.
  • Review packed, obfuscated, or invalidly signed binaries carefully, but expect false positives from legitimate software installers and protection tools.
  • Correlate process injection or process hollowing signals with network activity and persistence artifacts to reduce noise.
  • For web-protocol C2 hunting, baseline normal destinations and user-agent or traffic patterns before treating generic HTTP/S traffic as suspicious.

Mitigation priorities

  • Start with inventory and telemetry coverage for Windows, Linux, and macOS endpoints because the ATT&CK object is multiplatform.
  • Harden and monitor persistence mechanisms: Windows Task Scheduler and cron should have change monitoring, ownership review, and least-privilege administration.
  • Apply application control, script control, and code-signing validation where operationally feasible to reduce unauthorized RAT execution and misleading binaries.
  • Limit unnecessary scripting and shell access, and log administrative command execution with sufficient command-line detail.
  • Use endpoint protection capable of observing memory-level behaviors such as process injection, not only file signatures.
Additional notes and limits

The ATT&CK record identifies NETWIRE as a publicly available, multiplatform RAT used by criminal and APT groups since at least 2012. Relationship context links it to APT33, SilverTerrier, The White Company, and TA2541, and maps it to techniques spanning execution, persistence, privilege escalation, defense evasion, discovery, credential access, collection, and command-and-control. The strongest defensive value is using those mapped behaviors to check whether SOC and IR coverage works across operating systems and does not depend solely on static malware naming.

No official ATT&CK detection guidance, aliases, labels, or tactics are supplied for the NETWIRE object itself. The recommendations above are derived from supplied ATT&CK relationships and platform fields, not from claims of current activity, confirmed customer exposure, or guaranteed detection. Local environment baselines, approved administration patterns, EDR capabilities, and network architecture are required to determine actual risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

NETWIRE

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

45 rows
DomainIDNameRelationship / procedure
EnterpriseT1090Proxy

NETWIRE can implement use of proxies to pivot traffic.[4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

NETWIRE creates a Registry start-up entry to establish persistence.[2][4][5][6]

EnterpriseT1027.002Software PackingSub-technique

NETWIRE has used .NET packer tools to evade detection.[4]

EnterpriseT1573.001Symmetric CryptographySub-technique

NETWIRE can use AES encryption for C2 data transferred.[4]

EnterpriseT1560.003Archive via Custom MethodSub-technique

NETWIRE has used a custom encryption algorithm to encrypt collected data.[7]

EnterpriseT1204.002Malicious FileSub-technique

NETWIRE has been executed through luring victims into opening malicious documents.[7][5][6]

EnterpriseT1204.001Malicious LinkSub-technique

NETWIRE has been executed through convincing victims into clicking malicious links.[7][5]

EnterpriseT1119Automated Collection

NETWIRE can automatically archive collected data.[4]

EnterpriseT1547.013XDG Autostart EntriesSub-technique

NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems.[4]

EnterpriseT1059.005Visual BasicSub-technique

NETWIRE has been executed through use of VBScripts.[7][6]

EnterpriseT1027Obfuscated Files or Information

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.[7]

EnterpriseT1059.001PowerShellSub-technique

The NETWIRE binary has been executed via PowerShell script.[7]

EnterpriseT1055Process Injection

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.[4]

EnterpriseT1053.003CronSub-technique

NETWIRE can use crontabs to establish persistence.[4]

EnterpriseT1027.011Fileless StorageSub-technique

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.[4]

EnterpriseT1083File and Directory Discovery

NETWIRE has the ability to search for files on the compromised host.[6]

EnterpriseT1057Process Discovery

NETWIRE can discover processes on compromised hosts.[7]

EnterpriseT1059.004Unix ShellSub-technique

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.[4][6]

EnterpriseT1049System Network Connections Discovery

NETWIRE can capture session logon details from a compromised host.[7]

EnterpriseT1560Archive Collected Data

NETWIRE has the ability to compress archived screenshots.[4]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.[7][4][6]

EnterpriseT1566.002Spearphishing LinkSub-technique

NETWIRE has been spread via e-mail campaigns utilizing malicious links.[5]

EnterpriseT1555Credentials from Password Stores

NETWIRE can retrieve passwords from messaging and mail client applications.[4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.[4]

EnterpriseT1102Web Service

NETWIRE has used web services including Paste.ee to host payloads.[7]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

NETWIRE can copy itself to and launch itself from hidden folders.[4]

EnterpriseT1010Application Window Discovery

NETWIRE can discover and close windows on controlled systems.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

NETWIRE can issue commands using cmd.exe.[4][6]

EnterpriseT1036.001Invalid Code SignatureSub-technique

The NETWIRE client has been signed by fake and invalid digital certificates.[2]

EnterpriseT1056.001KeyloggingSub-technique

NETWIRE can perform keylogging.[2][3][7][4][6]

EnterpriseT1106Native API

NETWIRE can use Native API including CreateProcess GetProcessById, and WriteProcessMemory.[7]

EnterpriseT1053.005Scheduled TaskSub-technique

NETWIRE can create a scheduled task to establish persistence.[7]

EnterpriseT1113Screen Capture

NETWIRE can capture the victim's screen.[2][7][4][6]

EnterpriseT1547.015Login ItemsSub-technique

NETWIRE can persist via startup options for Login items.[4]

EnterpriseT1016System Network Configuration Discovery

NETWIRE can collect the IP address of a compromised host.[4][6]

EnterpriseT1071.001Web ProtocolsSub-technique

NETWIRE has the ability to communicate over HTTP.[4][6]

EnterpriseT1055.012Process HollowingSub-technique

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.[7][4]

EnterpriseT1112Modify Registry

NETWIRE can modify the Registry to store its configuration information.[4]

EnterpriseT1082System Information Discovery

NETWIRE can discover and collect victim system information.[2]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.[5][6]

EnterpriseT1074.001Local Data StagingSub-technique

NETWIRE has the ability to write collected data to a file created in the ./LOGS directory.[7]

EnterpriseT1095Non-Application Layer Protocol

NETWIRE can use TCP in C2 communications.[4][5]

EnterpriseT1573Encrypted Channel

NETWIRE can encrypt C2 communications.[4]

EnterpriseT1543.001Launch AgentSub-technique

NETWIRE can use launch agents for persistence.[4]

EnterpriseT1105Ingress Tool Transfer

NETWIRE can downloaded payloads from C2 to the compromised host.[7][6]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0089: The White Company

The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.[1]

GroupEnterprise

G0064: APT33

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.[1][2]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.6
Created
Modified
Raw hash
eee1a6ece6a9c81f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.6Current bundleeee1a6ece6a9…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye APT33 Sept 2017

    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

    Open source URL
  2. [2]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  3. [3]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  4. [4]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  5. [5]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  6. [6]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  7. [7]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  8. [8]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  9. [9]
    Unit42 SilverTerrier 2018

    Unit42. (2016). SILVERTERRIER: THE RISE OF NIGERIAN BUSINESS EMAIL COMPROMISE. Retrieved November 13, 2018.

    Open source URL
  10. [10]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  11. [11]
    FireEye APT33 Sept 2017

    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

    Open source URL
  12. [12]
    FireEye APT33 Sept 2017

    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

    Open source URL
  13. [13]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  14. [14]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  15. [15]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  16. [16]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  17. [17]
    NETWIRE

    (Citation: FireEye APT33 Sept 2017) (Citation: FireEye APT33 Webinar Sept 2017) (Citation: McAfee Netwire Mar 2015)

  18. [18]
    NETWIRE

    (Citation: FireEye APT33 Sept 2017) (Citation: FireEye APT33 Webinar Sept 2017) (Citation: McAfee Netwire Mar 2015)

  19. [19]
    NETWIRE

    (Citation: FireEye APT33 Sept 2017) (Citation: FireEye APT33 Webinar Sept 2017) (Citation: McAfee Netwire Mar 2015)

  20. [20]
    mitre-attackS0198
    Open source URL
  21. [21]
    mitre-attackS0198
    Open source URL
  22. [22]
    mitre-attackS0198
    Open source URL
  23. [23]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  24. [24]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  25. [25]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  26. [26]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  27. [27]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  28. [28]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  29. [29]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  30. [30]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  31. [31]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  32. [32]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  33. [33]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  34. [34]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  35. [35]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  36. [36]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  37. [37]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  38. [38]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  39. [39]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  40. [40]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  41. [41]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  42. [42]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  43. [43]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  44. [44]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  45. [45]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  46. [46]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  47. [47]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  48. [48]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  49. [49]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  50. [50]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  51. [51]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  52. [52]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  53. [53]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  54. [54]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  55. [55]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  56. [56]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  57. [57]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  58. [58]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  59. [59]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  60. [60]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  61. [61]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  62. [62]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  63. [63]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  64. [64]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  65. [65]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  66. [66]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  67. [67]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  68. [68]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  69. [69]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  70. [70]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  71. [71]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  72. [72]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  73. [73]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  74. [74]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  75. [75]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  76. [76]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  77. [77]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  78. [78]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  79. [79]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  80. [80]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  81. [81]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  82. [82]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  83. [83]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  84. [84]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  85. [85]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  86. [86]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  87. [87]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  88. [88]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  89. [89]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  90. [90]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  91. [91]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  92. [92]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  93. [93]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  94. [94]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  95. [95]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  96. [96]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  97. [97]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  98. [98]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  99. [99]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  100. [100]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  101. [101]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  102. [102]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  103. [103]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  104. [104]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  105. [105]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  106. [106]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  107. [107]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  108. [108]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  109. [109]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  110. [110]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  111. [111]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  112. [112]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  113. [113]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  114. [114]
    FireEye APT33 Sept 2017

    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

    Open source URL
  115. [115]
    FireEye APT33 Sept 2017

    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

    Open source URL
  116. [116]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  117. [117]
    FireEye APT33 Webinar Sept 2017

    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

    Open source URL
  118. [118]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  119. [119]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  120. [120]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  121. [121]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  122. [122]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  123. [123]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  124. [124]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  125. [125]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  126. [126]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  127. [127]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  128. [128]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  129. [129]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  130. [130]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  131. [131]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  132. [132]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  133. [133]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  134. [134]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  135. [135]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  136. [136]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  137. [137]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  138. [138]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  139. [139]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  140. [140]
    Unit42 SilverTerrier 2018

    Unit42. (2016). SILVERTERRIER: THE RISE OF NIGERIAN BUSINESS EMAIL COMPROMISE. Retrieved November 13, 2018.

    Open source URL
  141. [141]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  142. [142]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  143. [143]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  144. [144]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  145. [145]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  146. [146]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  147. [147]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  148. [148]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  149. [149]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  150. [150]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  151. [151]
    FireEye NETWIRE March 2019

    Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

    Open source URL
  152. [152]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.