Nokoyawa is a 64-bit Windows ransomware family first identified in February 2022. It is assessed as an evolution of the Nemty-derived Karma lineage and has been associated with ransomware-as-a-service activity and affiliates including Microsoft-tracked DEV-0237. Public reporting has also identified operational and tradecraft overlaps with Hive and Play, although a direct code-based relationship with Hive is not established. Nokoyawa has been linked to the broader JSWORM, Karma, Nemty, and Nefilim ransomware ecosystem.
Nokoyawa conducts double-extortion operations: operators steal sensitive data before encrypting files and threaten public disclosure if ransom demands are not met. Variants encrypt local files and can be configured to encrypt network shares and hidden drives. They delete Windows Volume Shadow Copies, impairing recovery, and use partial encryption of larger files to accelerate impact. The ransomware has evolved from C/C++ implementations using SECT233R1 elliptic-curve cryptography and Salsa20 to Rust-based variants using Curve25519/X25519 and Salsa20. The closely related Nevada variant adds self-deletion after encryption.
Observed intrusions have involved phishing-delivered IcedID followed by Cobalt Strike, credential access, Active Directory and network discovery, Remote Desktop Protocol movement, and remote ransomware deployment using administrative tooling. Nokoyawa has also been deployed following exploitation of multiple Windows Common Log File System privilege-escalation vulnerabilities, including CVE-2023-28252, after attackers had already gained initial access. Reported targeting has included small and medium-sized organizations in the Middle East, North America, Asia, and South America, with Argentina notably represented in early activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-28252 is actively exploited in the wild by cybercriminals to escalate privileges and deploy the Nokoyawa ransomware payload.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CVE-2023-28252 is actively exploited in the wild by cybercriminals to escalate privileges and deploy the Nokoyawa ransomware payload.
In May 2022, DEV-0237 started to routinely deploy Nokoyawa, a payload that we observed the group previously experimenting with when they weren’t using Hive.
Five minutes after transferring the files to hosts in the domain, the Nokoyawa ransomware binary was executed on a domain controller... The time to ransomware (TTR) was just over 12 hours from the initial infection.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft disclosed a zero-day vulnerability in the Windows Common Log File System (CLFS), which cybercriminals are actively exploiting to deploy Nokoyawa ransomware payloads. The vulnerability, tracked as CVE-2023-28252 ... is a Privilege Escalation vulnerability in the Windows Common Log File System Driver ... Successful exploitation enables threat actors to gain SYSTEM privileges
In addition, Nokoyawa 1.1 is the only variant that obfuscates the Windows API functions that are called during runtime by resolving each name via CRC32 hash.
In order to reduce the risk of law enforcement actions, Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID... and the latter calls GetUserDefaultUILanguage... to determine the system's locale and language, respectively.
The configuration parameter is a Base64 encoded JSON object that has the following keys and values shown in Table 2... ENCRYPT_NETWORK Encrypt network shares
In order to reduce the risk of law enforcement actions, Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID... and the latter calls GetUserDefaultUILanguage... to determine the system's locale and language, respectively.
Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID for language IDs ... and the latter calls GetUserDefaultUILanguage ... to determine the system's locale and language, respectively.
After exploitation, attackers must still establish command and control (C2) communications before finally delivering and deploying the Nokoyawa strain of ransomware. The report provides additional indicators of compromise (IoCs) related to these and other stages of the campaign, including the Cobalt Strike Beacon domains used for C2.
Threat actors deploying Nokoyawa ransomware are known to employ the double extortion technique, where data is exfiltrated prior to ransomware deployment | Microsoft disclosed a zero-day vulnerability in the Windows Common Log File System (CLFS), which cybercriminals are actively exploiting to deploy Nokoyawa ransomware payloads.
There are a few commonalities between all Nokoyawa variants such as being compiled only for 64-bit versions of Windows and using a relatively obscure method to delete Windows Shadow Copies. The latter entails calling the function DeviceIoControl ... with the undocumented control code parameter IOCTL_VOLSNAP_SET_MAX_DIFF_AREA_SIZE (0x53C028) with a maximum size of 1, which causes Windows to delete all shadow copies as a result.
Nokoyawa 1.1 also has a --safe-mode command-line option to reboot the system into Windows safe mode prior to file encryption to maximize the number of files that can be encrypted by loading the minimal set of applications, and therefore, minimize the number of open file handles that may interfere with encryption.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family with strong TTP and possible personnel overlap with Play.
A ransomware family assessed as an evolution of the Nemty strain Karma. It encrypts local files and optionally network shares, excludes certain folders and extensions, uses dynamically loaded bcrypt.dll with BCryptGenRandom to seed an ephemeral Sect233r1 key pair, derives a shared Salsa20 key for file encryption, appends its ransomware extension, and drops a ransom note threatening data leakage.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Ransomware payload delivered after exploitation of CLFS privilege-escalation vulnerabilities; the campaign discussed was intended to culminate in Nokoyawa deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.