verified bitcoin address

NetWalker Ransomeware

NetWalker ransomware (a.k.a. “Mailto”)

NetWalker is the name used for a ransomware program and the associated ransomware-as-a-service (RaaS) criminal operation that emerged in 2019. Under the RaaS model, a small core of operators (often described as developers/administrators) provides the malware and infrastructure, while affiliates break into victim networks, deploy the ransomware, and share proceeds with the operators. (securityweek.com)

What it did

NetWalker was used to:

  • Encrypt victim files to disrupt operations, and
  • Commonly steal data and threaten publication to increase pressure to pay (a form of “double extortion”), using dark-web (“Tor”) leak infrastructure. (news.sophos.com)

Victims reported in public law-enforcement and security reporting included companies and public-sector bodies, such as municipalities, hospitals/healthcare organizations, emergency services, law enforcement, and educational institutions. (justice.gov)

Notable period and targeting

NetWalker became particularly notorious during the COVID-19 pandemic, when it was reported to have targeted healthcare organizations while the sector was under acute operational strain. (justice.gov)

Law-enforcement disruption and prosecutions

A major disruption effort occurred around January 2021, described as a coordinated law-enforcement action that disabled dark-web resources associated with the group and coincided with arrests/seizures connected to NetWalker activity. (cfr.org)

One of the most prominent publicly identified participants is Sébastien Vachon-Desjardins (Canada), described by U.S. prosecutors as a NetWalker participant/affiliate. He was arrested on January 27, 2021, later extradited to the United States, and was sentenced on October 4, 2022, to 20 years in prison and ordered to forfeit $21.5 million (with seizure details including substantial cryptocurrency holdings reported in the case materials). (justice.gov)

“Who is NetWalker?”

NetWalker is not a single person; it is best understood as:

  • a malware family (the ransomware), and
  • a criminal enterprise organized as a service-and-affiliate ecosystem (RaaS), with multiple participants performing different roles (development, access brokerage, deployment, negotiation, and money laundering). (securityweek.com)