- NetWalker is a “ransomware-as-a-service” that gains its access through COVID-19 phishing emails, encrypts infected systems and steals internal documents. Ransomware operators then threaten to publish victims’ documents if they fail to pay up.
- Victims, most of whom are large organizations such as companies and governments, appear to been obliging the hackers throughout the pandemic. McAfee and CipherTrace traced 2,795 bitcoin ($25 million) to NetWalker wallet addresses from March 1 through July 27.
- NetWalker’s developers refined their handling of bitcoin payments months before the pandemic began by swapping in SegWit addresses in place of legacy wallets, the report said.
- “This transition into SegWit could indicate that they are utilizing a new hardware wallet to store their BTC or just an indication of a desire for cheaper transactions,” said Pamela Clegg, director of financial investigations at CipherTrace.
- Clegg told CoinDesk that “large amounts of bitcoin” – up to 640 – appear to be sitting in cold storage. She said smaller amounts have been deposited at Russian crypto exchange CointoCard.org.
- The cybersecurity report follows last week’s warning from the FBI that NetWalker has been successfully exploiting COVID-19 in recent months. The FBI warns targeted institutions against paying hackers’ bitcoin ransom payments.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.