n3tworm logo

n3tworm

1 incidentes 1 paises 0 sectores ransomware IR Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
N3TW0RM is a ransomware group that emerged in May 2021, primarily targeting Israeli companies and, more broadly, organizations within the EMEA region. Assessed with high confidence to be of Iranian origin, its primary motivation is to disrupt Israeli interests rather than purely financial gain, evidenced by minimal ransom demands and a lack of engagement during negotiations. A distinctive characteristic of N3TW0RM is its use of a client-server model for ransomware deployment; a program is installed on the victim's server to listen for workstation connections, subsequently deploying client executables ('slave.exe') via PAExec to encrypt devices. This method allows the group to contain all ransomware activities within the victim's network, reducing reliance on external command and control infrastructure. The group also utilizes a disk space filler utility, an uncommon technique for ransomware operations, to overwhelm disk volumes with junk data before deleting it and shutting down the op
Tecnicas MITRE
T1059, T1562, T1078

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Iran (1)

Paises objetivo (SOCRadar)

United Arab EmiratesBahrainDjiboutiAlgeriaEgyptEritreaEthiopiaIsraelIraqJordan

Sectores objetivo (SOCRadar)

Construction of BuildingsManufacturingPublic AdministrationWholesale TradeEnergy & Utilities Clothing StoresAccommodation&Food ServicesTruck&Rail TransportationCivic&Social OrganizationsTelecommunications

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com