logo

Governmental Organizations are Targeted by Netwire RAT

ID: 690a7a8e-58ea-5373-9f4b-1c7ede3e1f8b

STIX ID: report--690a7a8e-58ea-5373-9f4b-1c7ede3e1f8b

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-05-27

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz observed a targeted spearphishing campaign delivering NetwireRAT to Pakistani government and other sector recipients via macro-enabled .docm attachments; the macro decodes a URL pointing to a compromised Nepalese college site, uses PowerShell to fetch and execute the Netwire payload which implements anti-analysis, persistence via registry keys, keylogging and proxy-based C2 communications to 66.42.43.177:443, and the report includes detailed IOCs and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.