The operators of the NetWalker ransomware are estimated to have earned over $25 million in ransom payments from their victims since March, security firm McAfee. While there are no clear statistics, the $25 million in earnings puts NetWalker at the top of the most successful ransomware gangs known today, which also includes other well-known ransomware such as Ryuk, Dharma, and REvil (Sodinokibi).
McAfee, which recently published a report on NetWalker's operations, was able to trace payments made by a victim to known Bitcoin associated with the ransomware gang. However, security researchers believe the gang could have done even more than its illegal operations .

NetWalker, as a ransomware strain, first appeared in August 2019. In its original version, the ransomware appeared under the name Mailto, but was renamed NetWalker in late 2019. The ransomware operates as a closed -access, a ransomware-as-a-service portal. Other hacker gangs register and go through a vetting process, which gives them access to an online portal where they can create customized versions of the ransomware. Distribution is left to these second-tier gangs, known as partners, and each group deploys it as it sees fit. Through this vetting process, NetWalker has recently begun selecting partners who specialize more in targeted attacks against networks of high-value, high-profile entities, rather than those who specialize in mass distribution methods such as exploit kits or spam emails. This is because targeting larger companies with precise operations allows the gang to demand more ransom as larger companies lose more profits when they are not operating, compared to smaller companies.
Specifically, the creator of NetWalker seems to favor partners who are able to perform interference via network attacks – on RDP servers, networking tools, VPN servers, firewalls, etc. It is worth noting that the creator of NetWalker, named Bugatti, was only interested in hiring Russian-speaking clients.

According to McAfee researchers, NetWalker has carried out attacks using exploits on Oracle WebLogic and Apache Tomcat servers, intruding into networks via RDP endpoints with weak credentials , or spear-phishing at major companies. However, according to an FBI alert published last week, Netwalker operators have also incorporated exploits for Pulse Secure VPN servers (CVE-201911510) and exploits for web applications using the Telerik UI component (CVE-2019-18935) to diversify their attack weapons.
US companies and government agencies have been warned to update their systems as there has been an increase in activity by the NetWalker gang, which has even affected some government networks. So far, the highest-profile victim of the NetWalker ransomware is Michigan State University, which was breached in late May as part of a series of attacks on several US. However, McAfee pointed out that NetWalker also poses a risk to companies around the world, and not just the US or Western Europe, which have also been targeted by NetWalker several times.

With over $25 million in ransom payments collected in recent months, NetWalker’s popularity is set to grow even further. And one of the reasons the NetWalker ransomware gang is so popular, having raked in over $25 million since March, is because of its “leak portal,” a site where the gang publishes names and data from victims who refuse to pay ransom.
One site operates on simple principles and is one of many ransomware leak sites. Once a NetWalker ransomware affiliate compromises a network, it first steals a company’s sensitive data and then encrypts files. If the victim refuses to pay for file decryption during initial negotiations, the ransomware gang creates an entry on its leak site. The entry has a timer, and if the victim still refuses to pay, the gang leaks the files it stole from the victim’s network.
The site has helped the NetWalker ransomware put additional pressure on victims, with many fearing that their intellectual property or sensitive data will be leaked online, while others fear that their names will be tarnished in the press, as the site and its latest victims are frequently mentioned in news articles, and many companies will pay just to have their name not be the first negative news story in the newspapers.
