Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

TTPs, infrastructure, and targeting history in one profile.
23 events from the most recent confirmed update back to the earliest known activity.
A cybersecurity industry source told BleepingComputer that Nefilim attacked Whirlpool during the first weekend of December 2020 and stole data before encrypting devices.
Whirlpool said it discovered ransomware in its environment in November 2020, contained the malware quickly, and later restored affected systems.
Qualys cites a May 2020 attack on Australia's Toll Group in which Nefilim allegedly leaked stolen data after the victim refused to pay.
By March 2020, Nefilim, CLOP, and Sekhmet had launched dedicated leak sites to publish stolen victim data from organizations that refused to pay.
Researchers documented Nefilim as a new ransomware family that encrypts files, threatens to leak stolen data if victims do not pay, and likely spreads through exposed RDP services.
Around March 2020, the operators rebranded the malware from Nemty to Nefilim and shifted to private affiliate cooperation for targeted extortion.
Nefilim activity began at the end of February 2020 as a new ransomware strain closely resembling Nemty 2.5 and using email-based ransom negotiations.
From the first half of 2020, the operators shut down the public ransomware-as-a-service model and shifted toward big-game hunting and targeted extortion.
Patches for CVE-2019-11634 and CVE-2019-19781 were released in January 2020, before later reports tied Nefilim intrusions to exploitation of unpatched Citrix systems.
The Citrix Gateway vulnerabilities CVE-2019-11634 and CVE-2019-19781, later cited as Nefilim intrusion vectors, were identified in December 2019.
In early October 2019, the Trik botnet started delivering Nemty to compromised systems and used an SMB-spreading component to propagate to additional hosts.
Nemty was first detected in August 2019, marking a substantial rewrite of the JSWorm lineage into a new branded ransomware family.
A July 2019 JSWorm 4.0.3 sample introduced RSA and a custom AES implementation, but remained decryptable because its pseudorandom number generator was not cryptographically secure.
From 2019 through the first half of 2020, JSWorm was run as a public ransomware-as-a-service operation and spread through channels including RIG exploit kit, Trik botnet, fake payment sites, and spam.
Researchers identified JSWorm in 2019 as the origin of a ransomware family that later rebranded multiple times, including as Nemty and Nefilim.
Over the weekend referenced in the report, Nefilim published stolen Whirlpool files on its leak site, including employee-related documents such as benefits, accommodation, medical, and background-check records.
Nef1lim-branded variants were documented on 14 July 2020 and again on 1 August 2020 using the .NEF1LIM extension and NEF1LIM-DECRYPT.txt ransom note.
Telegram-branded variants were documented on 15 June 2020 and 24 June 2020 using the .TELEGRAM extension and TELEGRAM-RECOVER.txt ransom note.
On 1 June 2020, a Sigareta variant was observed using the .SIGARETA extension and the ransom note SIGARETA-RESTORE.txt.
On 3 May 2020, an Offwhite variant was documented using the .OFFWHITE extension and the ransom note OFFWHITE-MANUAL.txt.
On 25 March 2020, a Nephilim-branded variant was documented using the .NEPHILIM extension and a ransom note named NEPHILIM-DECRYPT.txt.
The ID Ransomware profile states that Nefilim activity peaked in the first half to middle of March 2020.
By March 2020, the operators had created the Corporate Leaks/corpleaks.net site to publish stolen victim data as part of their double-extortion model.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 110 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceblog.qualys.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.