Nefilim is a Windows ransomware family active from early 2020 that conducts targeted, double-extortion attacks against organizations. It encrypts victim files using AES with RSA-protected key material, while operators steal sensitive data before encryption and threaten public disclosure if ransom demands are not met. Nefilim is widely assessed to share substantial code and operational lineage with Nemty, following a shift away from a public ransomware-as-a-service model toward more selective enterprise intrusions.
Operators have obtained initial access through exposed or brute-forced Remote Desktop Protocol services and exploitation of vulnerable Citrix remote-access appliances, including CVE-2019-19781. Post-compromise activity has included Active Directory reconnaissance, credential theft, lateral movement using PsExec and WMI, termination of security products and services, data staging and archiving, and exfiltration through cloud-synchronization tooling. The operation has used legitimate administrative and penetration-testing tools including AdFind, Cobalt Strike, Mimikatz, Process Hacker, PsExec, and MEGAsync.
Nefilim primarily targeted high-revenue enterprises across sectors including engineering, manufacturing, transportation, finance, professional services, energy, utilities, healthcare, and education. Confirmed victims include Toll Group and Stadler Rail. Swiss judicial proceedings found that a Ukrainian developer created code used by Nefilim, LockerGoga, and MegaCortex operations; U.S. authorities have separately charged Volodymyr Tymoshchuk as an alleged administrator of those operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
Nefilim targets vulnerabilities such as CVE-2019-11634 and CVE-2019-19781 in Citrix gateway devices, identified in December 2019 and patched in January 2020. | One of the more popular ransomware families over the last few months to switch to this extortion tactic was Nefilim. Nefilim ransomware emerged in March 2020 when Nemty operators quit the ransomware as a service model to concentrate their energy on more targeted attacks with more focused resources.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The court found the unnamed Ukrainian man to be the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families.
Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
Home appliances giant Whirlpool suffered a ransomware attack by the Nefilim ransomware gang who stole data before encrypting devices.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Nefilim has been observed to use a batch file for terminating certain processes and services.
AdFind can be used to discover computers, users, or groups with AD as a reconnaissance tool...
cybercriminals have weaponized this function for ransomware campaigns to discover and terminate arbitrary processes and services, including those that are antimalware-related.
As Process Hacker can be used to gain an overview of processes currently being used...
Le groupe est accusé d’avoir « volé des données » avant ou pendant les intrusions ransomware ; la section TTPs détectés liste explicitement T1041.
...an unnamed cybercriminal group that hacked corporate networks, stole data and encrypted systems to extort victims.
Le suspect est présenté comme le principal développeur des rançongiciels Lockergoga, Megacortex et Nefilim; Stadler Rail a été sommée de payer une rançon en bitcoin.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family allegedly developed by the convicted individual and used in worldwide corporate extortion attacks.
Ransomware family mentioned only in passing in relation to an unrelated Swiss criminal sentence.
Ransomware allegedly developed by the convicted suspect and identified as one of the ransomware families involved in attacks against organizations including Spie and Altran in January 2019.
Ransomware family that the convicted developer was found to have developed; the article does not specify its technical functionality beyond ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.