Nefilim, also widely referred to as Nephilim, was a ransomware operation active from 2020 that used an affiliate-based model and became associated with the broader shift toward double extortion. The group is commonly assessed as a successor or rebrand of Nemty and has also shown technical and ecosystem overlap with related JSWorm-family variants such as GangBang and Milihpen. Nefilim targeted large enterprises and other high-revenue organizations, including corporations in North America, Europe, and Australia, and publicly pressured victims through leak-site publication of stolen data when ransom demands were not met. The operation combined data theft with file encryption and tailored attacks to individual victims. Administrators provided affiliates with access to the ransomware and supporting infrastructure in exchange for a share of ransom proceeds. Victim selection emphasized larger companies, with reporting indicating a focus on organizations exceeding major annual revenue thresholds. Known victims include Whirlpool, and reporting also links the group to attacks affecting organizations in the United States and several European countries. Nefilim intrusions have been associated with lateral movement and post-compromise tooling common in enterprise ransomware operations. Reported behaviors include data exfiltration prior to encryption, use of PsExec for lateral movement, deployment of Cobalt Strike infrastructure, and use of credential-access and network-discovery tools such as Mimikatz, BloodHoundAD, AdFind, NetPass, and LaZagne. The malware ecosystem evolved across many closely related builds and extensions, indicating sustained development and repeated reconfiguration of keys, certificates, and branding. Fast-flux infrastructure has also been associated with Nefilim attacks. Law-enforcement actions have tied the operation to Ukrainian nationals. U.S. authorities alleged that Volodymyr Tymoshchuk acted as an administrator of Nefilim, in addition to LockerGoga and MegaCortex, while Artem Stryzhak pleaded guilty for his role as a Nefilim affiliate. These cases describe an organized ransomware enterprise in which administrators supplied malware and affiliates conducted intrusions and extortion. Nefilim’s use of affiliate operations, customized victim builds, and double extortion helped shape tactics that later became standard across the ransomware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the JSWorm-associated ransomware family showing similarity to Karma.
Referenced as a notable ransomware group known for leveraging fast-flux DNS networks.
Ransomware operations referenced in the context of U.S. legal action against an individual involved in Nefilim ransomware attacks.
Ransomware operations targeting corporations worldwide, using Nefilim ransomware and demanding ransom payments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.