Researchers said Nokoyawa is a 64-bit Windows ransomware family that evolved from the Karma/Nemty line rather than being closely related to Hive, revising earlier assessments that had tied it to Hive mainly through overlapping intrusion tradecraft. SentinelLabs found Nokoyawa shares core code patterns with Karma, including multithreaded encryption, command-line driven execution, Base64-encoded keys and ransom notes, dynamic loading of bcrypt.dll, and elliptic-curve key exchange to derive Salsa20 encryption keys. Earlier reporting had linked Nokoyawa to Hive because both were seen using tools such as Cobalt Strike, GMER, PC Hunter, PowerShell, and PsExec, but newer code-level analysis indicates those similarities are more consistent with a shared affiliate than a shared malware codebase.
Zscaler documented Nokoyawa’s progression from early C/C++ builds to a Rust rewrite and identified multiple variants, including Nokoyawa 2.0 and Nevada (2.1), which share more than 87% of their code. The newer strains use Curve25519 in place of earlier curves, accept a Base64-encoded JSON configuration on the command line, support encryption of network shares via the -network parameter, and perform partial encryption to speed attacks while appending a 40-byte footer to encrypted files. Across variants, the malware uses an uncommon DeviceIoControl call with IOCTL_VOLSNAP_SET_MAX_DIFF_AREA_SIZE to delete Windows Shadow Copies, while Nevada adds self-deletion and hardcoded encryption parameters; researchers also noted a flawed folder-hashing exclusion routine that can accidentally spare additional directories from encryption.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
In late September 2022, Nokoyawa was rewritten in Rust as Nokoyawa 2.0, replacing its earlier C implementation. The new version used Curve25519 with Salsa20 and accepted a Base64-encoded JSON configuration via the command line.
In March 2022, Trend Micro reported evidence suggesting Nokoyawa was likely connected to Hive based on overlapping tactics, tools, and one IP address indicating possible shared infrastructure. The report said Nokoyawa primarily targeted organizations in South America, especially Argentina.
SentinelLabs observed two samples of a new Nemty-derived variant dubbed Nokoyawa at the beginning of February 2022. The researchers assessed it as an evolution of Karma rather than a rebrand of Hive.
Researchers observed Karma samples compiled on June 18 and June 19, 2021, showing rapid iteration within days. Later samples added ransom notes, changed threading behavior, and evolved cryptographic components and note filenames.
SentinelLabs reported that the Karma ransomware threat actor was first observed in June 2021 and targeted numerous organizations across industries. The analysis traced rapid malware development across multiple closely timed builds.
Nefilim emerged in March 2020 and shared a substantial portion of code with NEMTY, though researchers assessed the operators likely acquired the code rather than being the same group. Unlike NEMTY's Tor payment portal model, Nefilim used email-based victim contact.
By early September 2019, researchers observed Nemty being delivered as a payload through RIG exploit kit malvertising campaigns targeting systems reliant on outdated technologies such as Internet Explorer and Flash Player. Mol69 documented the full infection chain in an AnyRun environment.
SentinelLabs stated that NEMTY launched in August 2019 as a public affiliate ransomware program before later going private. The same report says the family subsequently forked into a new version called NEMTY Revenue.
Nemty was described as a new ransomware family that appeared toward the end of August 2019, appending the .nemty extension, deleting shadow copies, and demanding about $1,000 through a Tor-hosted payment portal. Reporting also said a reliable source indicated the operators may have been deploying it via compromised RDP connections.
In 2019, FortiGuard Labs analyzed Nemty and found it used AES-128-CBC for file encryption, RSA-2048 for per-file protection, and an unusual embedded RSA-8192 public key for victim configuration data. The researchers also noted a hardcoded UserID that suggested an affiliate or RaaS-style operating model.
SentinelLabs later concluded that Nokoyawa was not a Hive rebrand and that prior claims of a close Hive relationship were unsupported by code similarities. The researchers instead assessed Nokoyawa as an evolution of the Nemty-derived Karma strain and documented features such as network-share encryption and flawed folder-hash exclusions.
ThreatLabz identified at least four distinct Nokoyawa versions—1.0, 1.1, 2.0, and 2.1—with version 2.1 referred to as Nevada. Their analysis found Nokoyawa 2.0 and Nevada shared more than 87% of their code, while Nevada added hardcoded parameters and self-deletion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 83 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
11 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcesentinelone.com
Open sourcesentinelone.com
Open sourcezscaler.com
Open sourcetrendmicro.com
Open sourcefortinet.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.