Nemty X is a historical ransomware-as-a-service operation associated with the broader Nemty ransomware lineage. It has been referenced alongside other financially motivated big-game-hunting and extortion-focused ransomware operations and is notable as part of the evolution of criminal affiliate ecosystems that combined enterprise intrusion activity with ransomware deployment. Nemty X is linked to the ransomware economy in which operators and affiliates monetize network compromise through encryption and extortion, and it has been discussed in relation to overlapping tactics, techniques, and procedures seen across later ransomware groups. High-confidence reporting supports classifying Nemty X as a ransomware family or variant within the Nemty ecosystem, but the available information here does not establish specific delivery vectors, platform scope beyond what is typical for enterprise ransomware, or a detailed capability set unique to this variant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical RaaS/ransomware operation with TTP overlap to INC Ransom (no additional details provided).
Ransomware family referenced as part of 2020 BGH landscape with a dedicated leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.