NetWire RAT is a is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012. In this scenario the NetWire RAT is distributed via through GuLoader.using Microsoft Word documents. The chain starts with fake email which contains a web link for a Microsoft Word document. The word document has macro code that retrieves a Windows executable for GuLoader. The executable retrieves an encrypted data file used for NetWire.
In previous campaigns of Netwire RAT the same procedure has been used to kickoff the infection chain and similar fake emails were followed up with the web links for the users to click on the malicious attachments and lures for malspam pushing NetWIre RAT.