Nefilim, also known as Nephilim, was a financially motivated ransomware operation first observed in 2020 and widely assessed as a successor to the Nemty ransomware family. It operated an affiliate-based ransomware-as-a-service model in which administrators supplied customized encryptors and extortion infrastructure while retaining a share of affiliate proceeds. Nefilim used double extortion: operators exfiltrated sensitive data, encrypted victim systems, and threatened public disclosure through its Corporate Leaks leak site when victims did not pay. Nefilim primarily pursued large, high-revenue enterprises, including targets in the United States, Canada, Australia, and Europe. Confirmed victim reporting includes organizations in industrial manufacturing, consumer products, telecommunications, and information technology. The operation was associated with attacks on Whirlpool, Stadler Rail, Orange, Luxottica, Toll Group, Dussmann Group, Meier Tobler, and Crealogix. Observed Nefilim intrusions involved data exfiltration, lateral movement using PsExec, credential-access tooling, Active Directory reconnaissance, and fast-flux infrastructure intended to make command-and-control and related services more resilient to blocking and takedown. Nefilim samples and closely related clusters evolved through changing encryption extensions, embedded keys, signing artifacts, and contact mechanisms. Code and operational overlap has been reported among Nefilim, Nemty, JSWorm, GangBang, and Milihpen-related variants. U.S. authorities have alleged that Ukrainian national Volodymyr Tymoshchuk administered Nefilim alongside the LockerGoga and MegaCortex operations. Ukrainian national Artem Stryzhak pleaded guilty in the United States for his role as a Nefilim affiliate. Nefilim activity declined after 2022 amid law-enforcement action, although investigations of its administrators and affiliates continued.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation developed in part by the convicted individual and linked to high-profile attacks including the 2020 Stadler Rail breach, which involved alleged data theft and ransom-based extortion.
Referenced as part of the JSWorm-associated ransomware family showing similarity to Karma.
Referenced as a notable ransomware group known for leveraging fast-flux DNS networks.
Ransomware operations referenced in the context of U.S. legal action against an individual involved in Nefilim ransomware attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.