Uptime Hamster: 21d 5h 26mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza n3tworm

n3tworm

2 incidentes 2 paises 0 sectores threat-actor IR Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
N3TW0RM is a ransomware group that emerged in May 2021, primarily targeting Israeli companies and, more broadly, organizations within the EMEA region. Assessed with high confidence to be of Iranian origin, its primary motivation is to disrupt Israeli interests rather than purely financial gain, evidenced by minimal ransom demands and a lack of engagement during negotiations. A distinctive characteristic of N3TW0RM is its use of a client-server model for ransomware deployment; a program is installed on the victim's server to listen for workstation connections, subsequently deploying client executables ('slave.exe') via PAExec to encrypt devices. This method allows the group to contain all ransomware activities within the victim's network, reducing reliance on external command and control infrastructure. The group also utilizes a disk space filler utility, an uncommon technique for ransomware operations, to overwhelm disk volumes with junk data before deleting it and shutting down the op

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: n3tworm
DLS / onionofflinen3twormruynhn3oetmxvasum2miix2jgg56xskdoyihra4wthvlgyeyd.onionCTI.FYI
Tecnicas MITRE
T1059, T1562, T1078
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Iran (1) United States (1)

Paises objetivo (OSINT)

United Arab EmiratesBahrainDjiboutiAlgeriaEgyptEritreaEthiopiaIsraelIraqJordan

Sectores objetivo (OSINT)

Construction of BuildingsManufacturingPublic AdministrationWholesale TradeEnergy & Utilities Clothing StoresAccommodation&Food ServicesTruck&Rail TransportationCivic&Social OrganizationsTelecommunications

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com