Nemty is a Windows ransomware family first observed in 2019 that operated as a file-encrypting and extortion malware, including in ransomware-as-a-service form. It encrypts victim files, deletes shadow copies and backups to hinder recovery, presents a ransom note, and uses Tor-based or email-based payment workflows depending on variant and lineage. Nemty has been associated with later families including Nefilim and has been described as part of the broader JSWorm evolutionary line; Nefilim in particular is widely assessed to share substantial code with Nemty 2.5 and to represent a later, more targeted evolution away from the public RaaS model.
Technically, Nemty variants have used hybrid cryptography with AES for file encryption and RSA for protecting key material, with some analyses noting embedded high-bit RSA public keys for protecting victim configuration data. Researchers also documented version-to-version changes including stronger cryptographic implementation, persistence via scheduled tasks, process and service termination to unlock files, storage of configuration and key material on the host, and pre-encryption deletion of shadow copies. Early builds showed implementation flaws and immature coding practices, while later versions became more operationally mature.
Nemty was distributed through multiple channels. Reported delivery mechanisms include the RIG exploit kit in malvertising-driven campaigns against systems reliant on outdated browser technologies, malicious spam, compromised or exposed remote desktop services, and delivery by the Trik botnet, also known as Phorpiex. Trik-linked propagation also involved SMB-based spreading using weak credentials. Nemty was additionally advertised in underground forums as a criminal service.
Operationally, Nemty adopted the double-extortion model seen across major ransomware operations, stealing unencrypted data before or alongside encryption and threatening public release if victims refused to pay. This placed it among the earlier ransomware families to combine file encryption with data-leak pressure. Reporting also links Nemty by code lineage or evolution to later ransomware families such as Nefilim and Nokoyawa.
Nemty primarily targets Windows environments and has been observed in both opportunistic and more targeted enterprise-focused intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on our observations on Nefilim attacks to date, our hypothesis is that Nefilim is a RaaS operation whose business model closely resembles that of Nemty, another RaaS operation first spotted in August 2019.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
It is most likely distributed through exposed Remote Desktop Protocol (RDP)... The new ransomware is most likely spread through RDP... Like Nefilim, many of these ransomware attacks abuse exposed RDP ports.
Security researcher Mol69 noticed that the file-encrypting malware is now a payload in malvertising campaigns from RIG exploit kit (EK).
There is evidence of an initial breach via exploitation of vulnerable server-side software (Citrix ADC) and unsecure RDP access.
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
It implements a minor anti-analysis trick consisting of a string obfuscation algorithm. The strings ... are encrypted by the RC4 stream cipher with a hardcoded key “fuckav” and encoded in Base64.
there is no free decryption tool available at the moment and the malware makes sure to remove the file shadows created by Windows.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
Upon launch, the sample will gather the information about storage devices attached to the infected machine, get its external IP address by an HTTP request to http://api.ipify.org
After achieving the privilege level needed, encryption usually occurs on the individual machine without lateral movement
Besides file encryption, it performs actions such as stopping a number of running processes and services to maximize the number of files available for encryption.
In addition, it deletes all system backups, shadow copies, disables the system recovery mode, and clears event logs.
The operators behind Sodinokibi Ransomware have published the download links to archives containing data allegedly stolen from the US firm Kenneth Cole Productions... threatens to leak online the full dump containing stolen data in case the company will decide to not meet the request.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family launched in August 2019 as a public affiliate program and later taken private. The content describes it as code-related to Nefilim/Nephilim and notes later variants using AES-128 and RSA-2048.
The broader ransomware family from which Karma originated and from which Nokoyawa is assessed to have evolved.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a well-known ransomware family linked by similarity to Karma.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.