Cyber Threat Actor: Netwalker
| Actor Type | Location | Known Incidents |
Crime Syndicate
|
—
|
33 incidents |
|---|
Profile
Netwalker, also identified as NetWalker or Circus Spider, is a financially motivated cybercriminal group specializing in ransomware operations. The group employs a ransomware-as-a-service (RaaS) model, enabling affiliate hackers to deploy their malware in exchange for a share of ransom payments. Their attacks consistently follow a double extortion strategy: encrypting victim data while exfiltrating sensitive information to pressure organizations into paying ransoms. Netwalker’s operations have targeted healthcare, education, government, energy, transportation, and legal services sectors across multiple regions, including the United States, Canada, Australia, France, Pakistan, Argentina, and Austria. High-profile incidents include the University of California San Francisco (UCSF), which paid a $1.14 million ransom, and attacks on healthcare providers like Lorien Health Services and the College of Nurses of Ontario during the COVID-19 pandemic, contradicting voluntary moratoriums observed by some ransomware groups.
The group leverages phishing campaigns, often exploiting current events like COVID-19, and vulnerabilities in exposed services such as Remote Desktop Protocol (RDP) and unpatched Citrix systems to gain initial access. Netwalker’s ransomware encrypts files and disrupts operations, accompanied by ransom notes instructing victims to contact operators via Tor-based payment sites. Stolen data is published on a dedicated leak site if demands are unmet, with countdown timers intensifying pressure. Notable ransom demands include $14 million from energy firm Enel Group and $4.5 million from data center provider Equinix. Netwalker affiliates have also exploited dark web forums to auction victim data, as seen in the Crozer-Keystone Health System breach. While no state sponsorship is indicated, the group’s collaboration with external hackers through RaaS and consistent global targeting underscore its organized criminal nature. The FBI has issued alerts regarding Netwalker’s increased activity, particularly against critical infrastructure and healthcare entities.
