BlackBerry Spark Stops NetWalker Fileless Ransomware

Опубликовано: 04 Май 2026
на канале: Cylance Inc.
1,889
25

NetWalker has become one of the most popular ransomware families in 2020, targeting companies of all sizes and more recently favouring educational and healthcare institutions. The ransomware is using the current COVID-19 crisis to deploy phishing campaigns that prey on individuals interested in learning more about the virus, including healthcare facility staff.

The ransomware started life as ‘Mailto’ ransomware back at the end of 2019 – fast forward six months, and it has now become “extremely active” as a ransomware-as-a-service (RaaS) operation, with its affiliates using it to target vulnerable Remote Desktop Services. The ransomware is primarily distributed via spam or phishing emails, or through larger-scale network infiltration. NetWalker affiliates claim they can now exfiltrate data from victims and post it online, an evolving trend made (in)famous by the Maze hacking group.

NetWalker has made a number of successful attacks to date, including one against Australian transportation company Toll Group, Asia Pacific's leading provider of logistics services, which has 44,000 employees in 1,200 locations spread over 50 countries.

The ransomware has also been targeting educational institutions, including Michigan State University, one of the oldest educational institutes in the U.S. NetWalker most recently impacted the University of California San Francisco (UCSF), breaching the UCSF School of Medicine’s IT network, stealing data and encrypting systems.

BlackBerry Spark Stops NetWalker Ransomware

Even though it seems like a regular ransomware infection, this technique is very interesting. It can affect both Windows 32-bit and 64-bit systems, and even when the malware is dropped successfully onto the device, both files are still extremely obfuscated with both being Microsoft .NET files that are custom packed.

The fact that the PowerShell script has the ability to build this ransomware makes it extremely dangerous; more so because the script has the ability to slightly modify the dynamic-link-libraries it produces, making the malware even more evasive.

The good news is that the BlackBerry Spark® Unified Endpoint Security (UES) Suite solution prevents this attack through a number of preventative capabilities such as script control and memory protection (via BlackBerry® Protect). Additionally, our context-analysis engine and one-liner machine learning module (BlackBerry® Optics) provides automated prevention and unparalleled visibility and response.

For more information about how BlackBerry Spark is helping organisations to combat ransomware and build cyber-resilient organisations, please visit our learning resources here: https://www.blackberry.com/us/en/solu....