NetWire Remote Access Trojan Being Spread by Phishing Campaign

Stu Sjouwerman | Oct 1, 2019

image.imgResearchers at Fortinet have come across a phishing campaign delivering a new version of the NetWire remote access Trojan (RAT). The phishing emails claim to contain invoices and encourage recipients to click on the attached PDF. The bottom of the email has an image of a PDF attachment which is actually a hyperlink to download the malware. When a victim tries to open the attachment, their computer will be infected with NetWire.

Once the RAT is on a system, it functions as a keylogger and sends a wide variety of information about the victim’s activity and device to the attacker. It also steals credentials stored by Chrome, Firefox, Opera, Outlook, and other browsers and services. Additionally, it can read, write, and delete data on the victim’s computer. It’s also worth noting that the new variant of NetWire uses an assortment of anti-sandboxing and anti-debugging techniques to prevent it from being analyzed.

This phishing campaign shows why users need to be able to spot suspicious emails right off the bat. Most people wouldn’t think to hover over a PDF attachment to check for a link before clicking on it. However, a vaguely worded email regarding an unexpected invoice could have put users on high alert before they tried to open the attachment. New-school security awareness training can teach your employees to constantly be on the lookout for signs that an email is fraudulent.

Fortinet has the story: https://www.fortinet.com/blog/threat-research/new-netwire-rat-variant-spread-by-phishing.html

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.