Netwalker Ransomware Adopts an Affiliate Model to Help Increase Attacks and Profits

Stu Sjouwerman | May 30, 2020

iStock-460313833The ransomware formerly known as Mailto has taken a page from traditional software vendors and rebranded itself with a new affiliate-based go-to-market strategy.

When I need new customers, I look for ways to quickly identify and reach potential prospects, which can often include a channel strategy that leverages partners and affiliates. So, it should come as no surprise to see that ransomware “vendors” are doing the very same thing. According to Bleeping Computer, the operators of the Netwalker have been conducting interviews (yeah! Interviews!!!) to identify appropriate affiliates since March that will help take advantage of those cybercriminal organizations that are really good at compromising credentials, use of social engineering, and infecting endpoints to help increase Netwalker’s reach.

According to the details uncovered, affiliates receive up to 70% of the ransom, giving cybercriminal organizations ample incentive to partner up with Netwalker.

With Netwalker operators touting paid ransoms as high as $1.5 million, this new age of multiple cybercriminal organizations ganging up together to be even more impactful should have you worried.

The good news is this new development only means Netwalker expands its’ potential for successful ransom; it does not ensure success however. Organizations that address the use of phishing attacks as one of the primary attack vectors can stop attacks by Netwalker affiliates in their tracks. With a layered security strategy and Security Awareness Training in place, users will both be protected from and can steer clear of advanced phishing attacks that may include Netwalker or any other malicious content.

Topics: Ransomware

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.