Open Nav
Sign Up

N3TW0RM Ransomware IOCS

Oran Cohen

May 5, 2021

Updated: 15:00 GMT 09/05/21

A new ransomware attack group called N3tw0rm is claiming to have penetrated the network of several Israeli companies included Veritas, an international shipping and logistics company, Ecolog, an infrastructure engineering company, and Israel’s branch of clothing retailer H&M. In a departure from previous behavior, a source familiar with the matter stated that after encryption the threat actors did not send H&M a ransom demand since their aim is to embarrass H&M.

N3tw0rm ransomware origins

There is speculation that this N3tw0rm group is associated with Iran. If confirmed, the group will be operating hot on the heels of Pay2Key, a group that attacked numerous companies including Intel, Portnox and IAI back in December 2020. OP Innovate was at the forefront of Israel’s response to Pay2Key and verifies that this new attack exhibits similarities in the MO of the Pay2Key attack. It may be timed to coincide with Israel’s upcoming Jerusalem Day. OP Innovate has put together a list of IOCs (indicators of compromise) we have been able to identify from our investigations so far:

IndicatorsTagsComments
8080PortPort between internal secondary and internal primary
C:\Windows\Temp\n3tw0rm\Slave.exe Path, File 
8C6FD14084820EC528749300222097D21197659535AAA50CDCC75831F73546C1 SHA256 
4AC7B7A9992CFD83912DC912105D615CMD5 
C:\Windows\Temp\n3tw0rm\FreeSpaceWorker.exePath, File 
B1B8DBA2291604B968482D65B6B53142B1BF50A8D5B7CD0D652E9C6BF6A3E1BBSHA256 
paexec-[#####]-[computername].exeFileTool in use (# are for random numbers)
85.203.15.19IP AddressC&C – Express VPN
85.203.15.35IP AddressC&C – Express VPN
s.exeFileServer
pp64.exeFilePypykatz
078667339385F3B77AEA2023C8FF9DB373841741SHA256Pypykatz hash

Protect yourselves from ransomware gangs

For more information on how OP Innovate‘s cybersecurity expertise can help protect your company’s vital assets from falling into the wrong hands, contact Shay Pinsker at shay@op-c.net.

Written by Oran Cohen, Chief Security Officer at OP innovate

Resources highlights

CVE-2026-25874: Critical Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE

A critical unpatched vulnerability has been disclosed in Hugging Face LeRobot, an open-source robotics platform used for AI-driven robotics research and development. The flaw, tracked…

Read more >

CVE-2026-25874

BlueHammer: Microsoft Defender Privilege Escalation (CVE-2026-33825)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-33825, also known as BlueHammer, to its Known Exploited Vulnerabilities (KEV) Catalog, confirming active exploitation…

Read more >

CVE-2026-33825

CISA Flags Actively Exploited Cisco SD-WAN Vulnerabilities (CVE-2026-20133, CVE-2026-20122, CVE-2026-20128)

CISA has added multiple Cisco Catalyst SD-WAN vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. These flaws affect SD-WAN…

Read more >

cisco sd-wan

Cyber Warfare Amid the Israel-Iran Conflict: What Organizations Need to Know

Launched in late February, the joint U.S.-Israeli airstrike campaign against Iran (codenamed Operation Epic Fury/Roaring Lion) was quickly met with retaliatory cyberattacks. Iran’s hackers wasted…

Read more >

Iran cyber activity

nginx-ui Unauthenticated Takeover Vulnerability Actively Exploited (CVE-2026-33032)

CVE-2026-33032 is a critical authentication bypass vulnerability affecting nginx-ui (≤ 2.3.5). The issue arises from inconsistent security controls applied to MCP endpoints: while the /mcp…

Read more >

CVE-2026-33032

CISA Flags Actively Exploited Microsoft Office and SharePoint Vulnerabilities (CVE-2009-0238, CVE-2026-32201)

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, confirming active exploitation in the wild. The inclusion of both a legacy Microsoft…

Read more >

CVE-2009-0238, CVE-2026-32201
Under Cyber Attack?

Fill out the form and we will contact you immediately.