Skip to content

Global Crackdown on NetWire RAT: Croatian Admin Arrested, Infrastructure Seized

The international effort to combat NetWire RAT has resulted in the arrest of its alleged administrator. The seizure of servers and websites could signal the end of this powerful spying tool.

This looks like a name board, which is fixed to the wall. I think these are the screws. I can see...
This looks like a name board, which is fixed to the wall. I think these are the screws. I can see the logo and the letters on the name board.

Global Crackdown on NetWire RAT: Croatian Admin Arrested, Infrastructure Seized

Authorities worldwide have dealt a significant blow to the NetWire Remote Access Trojan (RAT) operation. The Croatian police have revealed a link between Mario Zanko and the distribution of this malicious software. Meanwhile, law enforcement in Switzerland has seized the server hosting the NetWire infrastructure, and the U.S. Federal Bureau of Investigation (FBI) has taken control of the NetWire sales website.

NetWire, a stealthy and powerful tool for spying on infected systems and stealing passwords, has been a concern for cybersecurity experts since its appearance on cybercrime forums in 2012. Capable of targeting multiple platforms, including Windows, Android, Linux, and Mac, NetWire infections have consistently ranked among the top 10 most active RATs in use.

The U.S. Department of Justice (DOJ) joined the international effort, seizing the NetWire website's domain as part of a coordinated law enforcement action. Authorities in Croatia have arrested a Croatian national suspected of being the administrator of the NetWire website. Mario Zanko, who is believed to be the owner of the site, was detained for three months in connection with the investigation.

The arrest of the alleged NetWire administrator and the seizure of its infrastructure and website mark a substantial step in dismantling this long-standing cyber threat. The international cooperation among law enforcement agencies demonstrates a commitment to combating the spread of Remote Access Trojans and protecting users across platforms.

Read also:

Latest