Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
Nefilim
Nefilim is a human-operated double-extortion ransomware family first observed in early 2020 and widely assessed as closely related to, or evolved from, Nemty.
Profile source: Mallory opens in a new tabNefilim
Family profile
Nefilim is a human-operated double-extortion ransomware family first observed in early 2020 and widely assessed as closely related to, or evolved from, Nemty. It encrypts victim files and steals sensitive data prior to encryption, then threatens public disclosure of the stolen information to coerce payment. The family has been associated with targeted intrusions against large enterprises, including organizations in manufacturing, logistics, education, and other sectors, and has been noted for pursuing high-revenue companies.
Nefilim commonly gained initial access through exposed or brute-forced Remote Desktop services and through exploitation of Citrix ADC and Citrix Gateway vulnerabilities, including CVE-2019-19781 and CVE-2019-11634. Campaigns relied heavily on hands-on-keyboard activity after access was obtained. Operators and affiliates used credential theft utilities such as Mimikatz, LaZagne, and NirSoft NetPass; reconnaissance tools such as AdFind and BloodHound; and remote execution or lateral movement mechanisms including PsExec and WMI. Intrusions also used tools such as Cobalt Strike for post-exploitation, Process Hacker and similar utilities to terminate security-related processes and services, and archiving and synchronization software such as 7-Zip and MEGAsync to stage and exfiltrate stolen data.
The ransomware itself uses AES-128 for file encryption and protects per-file key material with an embedded RSA-2048 public key. It appends a distinctive extension to encrypted files, writes ransom notes, and has been reported to include anti-debugging checks and self-deletion behavior. Nefilim campaigns exemplified the broader shift from commodity ransomware-as-a-service toward more selective enterprise extortion operations in which the malware binary was only one component of a larger intrusion workflow.
Nefilim has also been linked to a broader lineage that includes JSWorm and later rebrandings or closely related variants. The group operated a leak site branded as Corporate Leaks to publish data from non-paying victims, reinforcing its role in the normalization of ransomware-driven data breach extortion.
Capabilities
- Brute Force
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Initial Access
- Lateral Movement
- Post Exploitation
- Reconnaissance
Operational record
Reported operators
Threat actors
3 named in public reportingTo better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
Home appliances giant Whirlpool suffered a ransomware attack by the Nefilim ransomware gang who stole data before encrypting devices.
Exploited software
Vulnerabilities linked to Nefilim
3 CVEsMITRE ATT&CK
Nefilim in ATT&CK
54 distinct techniquesTechniques
54 techniquesReporting
Research mentioning Nefilim
A Detailed Walkthrough of Ranzy Locker Ransomware TTPs
Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.
Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative - SentinelLabs
Popular hacking forum bans ransomware ads | The Record from Recorded Future News
The Russian-speaking cybercrime forum XSS banned all ransomware-related topics, including affiliate program advertisements, ransomware rentals, and sales of ransomware software. The forum’s administrator said ransomware had brought excessive publicity and law-enforcement attention to the site, with scrutiny intensifying after the DarkSide attack on Colonial Pipeline. Researchers cited in the reports said XSS had been one of the main underground venues used by ransomware groups to recruit affiliates and promote ransomware-as-a-service operations. The move drew negative reactions from representatives linked to REvil and LockBit, underscoring how important major forums were to the ransomware ecosystem. A day later, Exploit, another major Russian-language cybercrime forum, reportedly imposed a similar ban on ransomware advertisements. The back-to-back restrictions suggested that pressure from high-profile attacks, political fallout, and increased law-enforcement focus was forcing prominent underground platforms to distance themselves from overt ransomware promotion.
Evolution of JSWorm ransomware | Securelist
Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.