CSIDB logo
Threat actor

Netwalker

Attribution profile

Type
Crime Syndicate
Location
-
Known incidents
33 incidents
Sources
24 sources
First seen
2019-08-09
Last seen
2021-05-22
Updated
2026-07-16 14:37
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Netwalker, also identified as NetWalker or Circus Spider, is a financially motivated cybercriminal group specializing in ransomware operations. The group employs a ransomware-as-a-service (RaaS) model, enabling affiliate hackers to deploy their malware in exchange for a share of ransom payments. Their attacks consistently follow a double extortion strategy: encrypting victim data while exfiltrating sensitive information to pressure organizations into paying ransoms. Netwalker’s operations have targeted healthcare, education, government, energy, transportation, and legal services sectors across multiple regions, including the United States, Canada, Australia, France, Pakistan, Argentina, and Austria. High-profile incidents include the University of California San Francisco (UCSF), which paid a $1.14 million ransom, and attacks on healthcare providers like Lorien Health Services and the College of Nurses of Ontario during the COVID-19 pandemic, contradicting voluntary moratoriums observed by some ransomware groups.

The group leverages phishing campaigns, often exploiting current events like COVID-19, and vulnerabilities in exposed services such as Remote Desktop Protocol (RDP) and unpatched Citrix systems to gain initial access. Netwalker’s ransomware encrypts files and disrupts operations, accompanied by ransom notes instructing victims to contact operators via Tor-based payment sites. Stolen data is published on a dedicated leak site if demands are unmet, with countdown timers intensifying pressure. Notable ransom demands include $14 million from energy firm Enel Group and $4.5 million from data center provider Equinix. Netwalker affiliates have also exploited dark web forums to auction victim data, as seen in the Crozer-Keystone Health System breach. While no state sponsorship is indicated, the group’s collaboration with external hackers through RaaS and consistent global targeting underscore its organized criminal nature. The FBI has issued alerts regarding Netwalker’s increased activity, particularly against critical infrastructure and healthcare entities.

Incidents

Attributed incidents are available to members.

33 incidents

Sources

Sources available to members: 24 sources.

CSIDB