NETWIRE

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[NETWIRE](https://attack.mitre.org/software/S0198) is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.(Citation: FireEye APT33 Sept 2017)(Citation: McAfee Netwire Mar 2015)(Citation: FireEye APT33 Webinar Sept 2017)

Associated Techniques (45)
ID ATT&CK Tactics
T1010 Application Window Discovery -
T1016 System Network Configuration Discovery -
T1027 Obfuscated Files or Information -
T1027.002 Software Packing -
T1027.011 Fileless Storage -
T1036.001 Invalid Code Signature -
T1036.005 Match Legitimate Resource Name or Location -
T1049 System Network Connections Discovery -
T1053.003 Cron -
T1053.005 Scheduled Task -
T1055 Process Injection -
T1055.012 Process Hollowing -
T1056.001 Keylogging -
T1057 Process Discovery -
T1059.001 PowerShell -
Metadata
ID: 109
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00