Names Circus Spider (CrowdStrike)
Country [Unknown]
Motivation Financial gain
First seen 2019
Description (Carbon Black) MailTo is a ransomware variant that has recently been reported to have been part of a targeted attack against Toll Group, an Australian freight and logistics company. This ransomware makes no attempt to remain stealthy, and quickly encrypts the user’s data as soon as the ransomware is launched. Once the encryption phase completes, the encrypted files are renamed to contain the word “mailto”, which is where the name originated from.
Observed Sectors: Education, Energy, Government, Healthcare, Manufacturing, Shipping and Logistics, Transportation.
Countries: Argentina, Australia, Austria, Belgium, Brazil, Canada, Chile, China, Colombia, France, Germany, Guatemala, Hungary, India, Iran, Ireland, Italy, Luxembourg, Malaysia, Netherlands, New Zealand, Nicaragua, Nigeria, Norway, Pakistan, Poland, Russia, Saudi Arabia, South Africa, Spain, Sweden, Thailand, Ukraine, USA, Vietnam.
Tools used NetWalker.
Operations performed Feb 2020 Ransomware Attack Hinders Toll Group Operations
Mar 2020 Netwalker Ransomware Infecting Users via Coronavirus Phishing
Mar 2020 Spanish hospitals targeted with coronavirus-themed phishing lures in Netwalker ransomware attacks
May 2020 Michigan State University hit by ransomware gang
May 2020 Ransomware recruits affiliates with huge payouts, automated leaks
Jun 2020 Netwalker ransomware continues assault on US colleges, hits UCSF
Jun 2020 Philadelphia-area health system says it 'isolated' a malware attack
Jul 2020 Netwalker Ransomware Stole Data After Targeting Lorien Health Services
Sep 2020 Netwalker ransomware hits Pakistan's largest private power utility
Sep 2020 Netwalker ransomware hits Argentinian government, demands $4 million
Sep 2020 Cyber threat startup Cygilant hit by ransomware
Sep 2020 Equinix data center giant hit by Netwalker Ransomware, $4.5M ransom
Oct 2020 Enel Group hit by ransomware again, Netwalker demands $14 million
Counter operations Jan 2021 Department of Justice Launches Global Action Against NetWalker Ransomware
Feb 2022 NetWalker ransomware affiliate sentenced to seven years in prison
Dec 2024 Romanian Netwalker ransomware affiliate sentenced to 20 years in prison
Information
Last change to this card: 27 December 2024