HC3 Threat Briefing TLP White - Netwalker Ransomware - September 24, 2020

Netwalker Ransomware was initially discovered in September 2019 with a compilation timestamp dating back to August 28, 2019. 

  • Also known as: Malito, Koko, KazKavKovKiz
  • Operated as Ransomware-as-a-Service (RaaS) by a cybercrime group known as CIRCUS SPIDER
    • Advertised as a closed-affiliate program, and verifies applicants before they are being accepted as an affiliate
  • Significant targeting in the Asia Pacific (APAC) region, but can reach globally
    • Often target hospitals in the US and Spain
    • Big game hunters
  • Ransom demands from $1K USD to $3M USD; use “double extortion”; over $25 million since March
  • Leveraging coronavirus and exploiting healthcare organizations during pandemic

View details below.