Skip to content

Nemty

Nemty was a Windows ransomware family operated as a ransomware-as-a-service platform active primarily from August 2019 through April 2020.

Profile source: Mallory opens in a new tab

Nemty

Family profile

Nemty was a Windows ransomware family operated as a ransomware-as-a-service platform active primarily from August 2019 through April 2020. It emerged after the JSWorm branding was reworked into Nemty, and it was part of the broader shift toward affiliate-driven ransomware operations and double-extortion schemes, including the use of leak sites to pressure victims.

Nemty’s operators maintained a web-based affiliate and victim-management panel and supported infrastructure features such as FastFlux-style domain protection. Reporting on the operation indicates recurring use of a relatively small affiliate pool, with some affiliates also participating in other ransomware programs such as GandCrab, Dharma, DJVU, Karma, Nokoyawa, and related ecosystems. Nemty has also been linked in reporting to actors and personas associated with other ransomware operations, including Volodymyr Tymoshchuk and aliases tied to JSWORM, Karma, and Nokoyawa.

The malware’s development cadence in 2019 showed rapid feature additions and operational refinement. Documented capabilities included faster multithreaded encryption, configurable file-extension exclusions, pre-encryption victim registration in the operator panel, and logic to terminate processes and stop services associated with databases, office applications, backup tooling, and virtualized environments in order to maximize file access and encryption impact. Later updates reportedly changed the encryption approach and introduced an internal key-generation mechanism. Nemty also supported payment-page configuration for affiliates and backend management features typical of mature RaaS offerings.

Nemty was used in financially motivated extortion campaigns against organizations, and like other contemporary ransomware families it fit the broader trend of combining encryption with data-theft pressure. It is historically notable as an early RaaS operation whose infrastructure and affiliate ecosystem overlapped with later ransomware activity and whose tradecraft showed continuity with subsequent families in the same criminal milieu.

Capabilities

  • Defense Evasion
  • Extortion

Operational record

1
YARA rules
3
Ransom notes
1
Leak sites
0 available

MITRE ATT&CK

Nemty in ATT&CK

10 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.