Description
NETWIRE is a remote access trojan sold commercially on underground forums for over a decade, and its buyers used it for surveillance and fraud across Windows, macOS, and Linux. It provides remote desktop control, password theft, and file management, and its long operational history produced many variants and loader relationships. Its developers shut the service down in 2020, but copies continue to circulate in criminal toolkits.
Stats
- First seen
- January 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
45 techniques across 9 tactics.
TA0002 Execution
TA0003 Persistence
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Backdoor.NetWire |
| Gen:Variant.NetWire.2 |
| GT:VB.Macros.NetWire.1.81F2D9CA |
| GT:VB.Macros.NetWire.2.56E43306 |
| GT:VB.Macros.NetWire.2.56E43306:03D2F |
| GT:VB.Macros.NetWire.2.56E43306:081EF |
| GT:VB.Macros.NetWire.2.56E43306:2B177 |
| GT:VB.Macros.NetWire.2.56E43306:365A2 |
| GT:VB.Macros.NetWire.2.56E43306:48CC3 |
| GT:VB.Macros.NetWire.2.56E43306:5D4DD |