Nefilim
Nefilim is a ransomware family and ransomware operation, also spelled "Nephilim," that emerged in March 2020 and is described as a successor to the Nemty ransomware family.
Profile source: Mallory opens in a new tabNefilim
Family profile
Nefilim is a ransomware family and ransomware operation, also spelled "Nephilim," that emerged in March 2020 and is described as a successor to the Nemty ransomware family. It operated as an affiliate-based ransomware scheme in which administrators provided affiliates with the malware and supporting resources in exchange for a share of ransom proceeds; multiple reports in the content state affiliates paid or surrendered 20% of ransom revenue to the administrators. The malware was used to encrypt victim networks worldwide and was paired with double-extortion tactics: operators stole data, encrypted systems, and threatened to publish stolen information on "Corporate Leaks" sites if victims did not pay. The operation generated customized ransomware executables, unique decryption keys, and tailored ransom notes for each victim. Reported targeting focused on large, high-revenue corporate victims, especially companies in the United States, Canada, and Australia, with references to thresholds above $100 million and later above $200 million in annual revenue. Victim industries mentioned in the content include aviation, engineering, chemicals, eyewear, insurance, construction, energy/oil and gas transportation, and pet care, with additional victims in the U.S., Germany, the Netherlands, Norway, Switzerland, France, and other countries. The content also notes Nefilim’s use in attacks causing millions of dollars in ransom and recovery losses. Operationally, Nefilim has been associated with fast-flux infrastructure, and Mandiant research cited process kill lists deployed alongside Nefilim samples. Trend Micro reporting in the content states Nefilim drops MegaSync into its normal file path under its normal name, consistent with data-exfiltration support tooling. The content links the operation to Ukrainian national Volodymyr Viktorovich Tymoshchuk, identified in charging documents as an administrator of the LockerGoga, MegaCortex, and Nefilim ransomware operations and currently at large, and to affiliate Artem Aleksandrovych Stryzhak, who pleaded guilty to deploying Nefilim against corporate networks after receiving access to the ransomware code in June 2021.
Operational record
MITRE ATT&CK