Uptime Hamster: 10d 19h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza n3tworm

n3tworm

2 incidentes 2 paises 0 sectores ransomware IR Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
N3TW0RM is a ransomware group that emerged in May 2021, primarily targeting Israeli companies and, more broadly, organizations within the EMEA region. Assessed with high confidence to be of Iranian origin, its primary motivation is to disrupt Israeli interests rather than purely financial gain, evidenced by minimal ransom demands and a lack of engagement during negotiations. A distinctive characteristic of N3TW0RM is its use of a client-server model for ransomware deployment; a program is installed on the victim's server to listen for workstation connections, subsequently deploying client executables ('slave.exe') via PAExec to encrypt devices. This method allows the group to contain all ransomware activities within the victim's network, reducing reliance on external command and control infrastructure. The group also utilizes a disk space filler utility, an uncommon technique for ransomware operations, to overwhelm disk volumes with junk data before deleting it and shutting down the op

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: n3tworm
Tecnicas MITRE
T1059, T1562, T1078
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Iran (1)

Paises objetivo (SOCRadar)

United Arab EmiratesBahrainDjiboutiAlgeriaEgyptEritreaEthiopiaIsraelIraqJordan

Sectores objetivo (SOCRadar)

Construction of BuildingsManufacturingPublic AdministrationWholesale TradeEnergy & Utilities Clothing StoresAccommodation&Food ServicesTruck&Rail TransportationCivic&Social OrganizationsTelecommunications

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com