n3tworm
1 incidentes
1 paises
0 sectores
ransomware IR Ultimo: 2026-06-25
N3TW0RM is a ransomware group that emerged in May 2021, primarily targeting Israeli companies and, more broadly, organizations within the EMEA region. Assessed with high confidence to be of Iranian origin, its primary motivation is to disrupt Israeli interests rather than purely financial gain, evidenced by minimal ransom demands and a lack of engagement during negotiations. A distinctive characteristic of N3TW0RM is its use of a client-server model for ransomware deployment; a program is installed on the victim's server to listen for workstation connections, subsequently deploying client executables ('slave.exe') via PAExec to encrypt devices. This method allows the group to contain all ransomware activities within the victim's network, reducing reliance on external command and control infrastructure. The group also utilizes a disk space filler utility, an uncommon technique for ransomware operations, to overwhelm disk volumes with junk data before deleting it and shutting down the op
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
BahrainDjibouti
Algeria
EgyptEritreaEthiopia
IsraelIraq
Jordan
Sectores objetivo (SOCRadar)
Construction of BuildingsManufacturingPublic AdministrationWholesale TradeEnergy & Utilities Clothing StoresAccommodation&Food ServicesTruck&Rail TransportationCivic&Social OrganizationsTelecommunications
URLs nuevas detectadas en IntelTracker