Skip to content

Nefilim

Nefilim is a human-operated double-extortion ransomware family first observed in early 2020 and widely assessed as closely related to, or evolved from, Nemty.

Profile source: Mallory opens in a new tab

Nefilim

Family profile

Nefilim is a human-operated double-extortion ransomware family first observed in early 2020 and widely assessed as closely related to, or evolved from, Nemty. It encrypts victim files and steals sensitive data prior to encryption, then threatens public disclosure of the stolen information to coerce payment. The family has been associated with targeted intrusions against large enterprises, including organizations in manufacturing, logistics, education, and other sectors, and has been noted for pursuing high-revenue companies.

Nefilim commonly gained initial access through exposed or brute-forced Remote Desktop services and through exploitation of Citrix ADC and Citrix Gateway vulnerabilities, including CVE-2019-19781 and CVE-2019-11634. Campaigns relied heavily on hands-on-keyboard activity after access was obtained. Operators and affiliates used credential theft utilities such as Mimikatz, LaZagne, and NirSoft NetPass; reconnaissance tools such as AdFind and BloodHound; and remote execution or lateral movement mechanisms including PsExec and WMI. Intrusions also used tools such as Cobalt Strike for post-exploitation, Process Hacker and similar utilities to terminate security-related processes and services, and archiving and synchronization software such as 7-Zip and MEGAsync to stage and exfiltrate stolen data.

The ransomware itself uses AES-128 for file encryption and protects per-file key material with an embedded RSA-2048 public key. It appends a distinctive extension to encrypted files, writes ransom notes, and has been reported to include anti-debugging checks and self-deletion behavior. Nefilim campaigns exemplified the broader shift from commodity ransomware-as-a-service toward more selective enterprise extortion operations in which the malware binary was only one component of a larger intrusion workflow.

Nefilim has also been linked to a broader lineage that includes JSWorm and later rebrandings or closely related variants. The group operated a leak site branded as Corporate Leaks to publish data from non-paying victims, reinforcing its role in the normalization of ransomware-driven data breach extortion.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

3 named in public reporting
Oleksandr Ieremenko

Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.

Water Roc

To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...

Nefilim ransomware gang

Home appliances giant Whirlpool suffered a ransomware attack by the Nefilim ransomware gang who stole data before encrypting devices.

Exploited software

Vulnerabilities linked to Nefilim

3 CVEs

MITRE ATT&CK

Nefilim in ATT&CK

54 distinct techniques

Techniques

54 techniques
T1486 Data Encrypted for Impact T1190 Exploit Public-Facing Application T1078 Valid Accounts T1041 Exfiltration Over C2 Channel T1537 Transfer Data to Cloud Account T1567 Exfiltration Over Web Service T1047 Windows Management Instrumentation T1133 External Remote Services T1003 OS Credential Dumping T1562 Impair Defenses T1657 Financial Theft T1021 Remote Services T1018 Remote System Discovery T1482 Domain Trust Discovery T1021.002 SMB/Windows Admin Shares T1057 Process Discovery T1489 Service Stop T1082 System Information Discovery T1567.002 Exfiltration to Cloud Storage T1074 Data Staged T1007 System Service Discovery T1110 Brute Force T1560 Archive Collected Data T1570 Lateral Tool Transfer T1083 File and Directory Discovery T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1070.004 File Deletion T1518.001 Security Software Discovery T1490 Inhibit System Recovery T1048 Exfiltration Over Alternative Protocol T1106 Native API T1005 Data from Local System T1055 Process Injection T1550 Use Alternate Authentication Material T1120 Peripheral Device Discovery T1070 Indicator Removal T1553.002 Code Signing T1135 Network Share Discovery T1189 Drive-by Compromise T1071 Application Layer Protocol T1020 Automated Exfiltration T1567.003 Exfiltration to Text Storage Sites T1204.002 Malicious File T1140 Deobfuscate/Decode Files or Information T1030 Data Transfer Size Limits T1566 Phishing T1021.001 Remote Desktop Protocol T1059 Command and Scripting Interpreter T1595.002 Vulnerability Scanning T1003.001 LSASS Memory T1068 Exploitation for Privilege Escalation T1568.001 Fast Flux DNS T1529 System Shutdown/Reboot

Reporting

Research mentioning Nefilim

Oct 28
Picus Security

A Detailed Walkthrough of Ranzy Locker Ransomware TTPs

Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.

Sep 2
Sentinelone Labs Subdomain

Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative - SentinelLabs

May 14
The Record Media

Popular hacking forum bans ransomware ads | The Record from Recorded Future News

The Russian-speaking cybercrime forum XSS banned all ransomware-related topics, including affiliate program advertisements, ransomware rentals, and sales of ransomware software. The forum’s administrator said ransomware had brought excessive publicity and law-enforcement attention to the site, with scrutiny intensifying after the DarkSide attack on Colonial Pipeline. Researchers cited in the reports said XSS had been one of the main underground venues used by ransomware groups to recruit affiliates and promote ransomware-as-a-service operations. The move drew negative reactions from representatives linked to REvil and LockBit, underscoring how important major forums were to the ransomware ecosystem. A day later, Exploit, another major Russian-language cybercrime forum, reportedly imposed a similar ban on ransomware advertisements. The back-to-back restrictions suggested that pressure from high-profile attacks, political fallout, and increased law-enforcement focus was forcing prominent underground platforms to distance themselves from overt ransomware promotion.

May 13
Securelist

Evolution of JSWorm ransomware | Securelist

Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

May 13
Bleeping Computer

Popular Russian hacking forum XSS bans all ransomware topics

May 12
Qualys

Nefilim Ransomware: Tactics, Impact, and Mitigation Strategies | Qualys

Feb 23
Trend Micro Research

An Analysis of the Nefilim Ransomware | Trend Micro (US)

Dec 28
Bleeping Computer

Home appliance giant Whirlpool hit in Nefilim ransomware attack

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.