Netskope Threat Labs

NETWIRE

ATP Sandbox Adv. HeuristicsAVNetskope IPS

NETWIRE is a remote access trojan sold commercially on underground forums for over a decade, and its buyers used it for surveillance and fraud across Windows, macOS, and Linux. It provides remote desktop control, password theft, and file management, and its long operational history produced many variants and loader relationships. Its developers shut the service down in 2020, but copies continue to circulate in criminal toolkits.

First seen
January 2022
Last seen
October 2026

45 techniques across 9 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores
  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1010Application Window Discovery
  • T1016System Network Configuration Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0009 Collection

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Backdoor.NetWire
Gen:Variant.NetWire.2
GT:VB.Macros.NetWire.1.81F2D9CA
GT:VB.Macros.NetWire.2.56E43306
GT:VB.Macros.NetWire.2.56E43306:03D2F
GT:VB.Macros.NetWire.2.56E43306:081EF
GT:VB.Macros.NetWire.2.56E43306:2B177
GT:VB.Macros.NetWire.2.56E43306:365A2
GT:VB.Macros.NetWire.2.56E43306:48CC3
GT:VB.Macros.NetWire.2.56E43306:5D4DD