Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0198
MITRE ATT&CK Malware

NETWIRE (S0198)

ShareXLinkedInRedditHN

[NETWIRE](https://attack.mitre.org/software/S0198) is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.(Citation: FireEye APT33 Sept 2017)(Citation: McAfee Netwire Mar 2015)(Citation: FireEye APT33 Webinar Sept 2017)

Platforms: Windows, Linux, macOS

▪Techniques implemented (45)

T1090ProxyT1547.001Registry Run Keys / Startup FolderT1027.002Software PackingT1573.001Symmetric CryptographyT1560.003Archive via Custom MethodT1204.002Malicious FileT1204.001Malicious LinkT1119Automated CollectionT1547.013XDG Autostart EntriesT1059.005Visual BasicT1027Obfuscated Files or InformationT1059.001PowerShellT1055Process InjectionT1053.003CronT1027.011Fileless StorageT1083File and Directory DiscoveryT1057Process DiscoveryT1059.004Unix ShellT1049System Network Connections DiscoveryT1560Archive Collected DataT1555.003Credentials from Web BrowsersT1566.002Spearphishing LinkT1555Credentials from Password StoresT1036.005Match Legitimate Resource Name or LocationT1102Web ServiceT1564.001Hidden Files and DirectoriesT1010Application Window DiscoveryT1059.003Windows Command ShellT1036.001Invalid Code SignatureT1056.001KeyloggingT1106Native APIT1053.005Scheduled TaskT1113Screen CaptureT1547.015Login ItemsT1016System Network Configuration DiscoveryT1071.001Web ProtocolsT1055.012Process HollowingT1112Modify RegistryT1082System Information DiscoveryT1566.001Spearphishing AttachmentT1074.001Local Data StagingT1095Non-Application Layer ProtocolT1573Encrypted ChannelT1543.001Launch AgentT1105Ingress Tool Transfer

▪Used by groups (4)

G0089The White CompanyG0064APT33G0083SilverTerrierG1018TA2541
S0198on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.