Skip to content

Nemty

Nemty is a Windows ransomware family first observed in 2019 that operated as a file-encrypting and extortion malware, including in ransomware-as-a-service form.

Profile source: Mallory opens in a new tab

Nemty

Family profile

Nemty is a Windows ransomware family first observed in 2019 that operated as a file-encrypting and extortion malware, including in ransomware-as-a-service form. It encrypts victim files, deletes shadow copies and backups to hinder recovery, presents a ransom note, and uses Tor-based or email-based payment workflows depending on variant and lineage. Nemty has been associated with later families including Nefilim and has been described as part of the broader JSWorm evolutionary line; Nefilim in particular is widely assessed to share substantial code with Nemty 2.5 and to represent a later, more targeted evolution away from the public RaaS model.

Technically, Nemty variants have used hybrid cryptography with AES for file encryption and RSA for protecting key material, with some analyses noting embedded high-bit RSA public keys for protecting victim configuration data. Researchers also documented version-to-version changes including stronger cryptographic implementation, persistence via scheduled tasks, process and service termination to unlock files, storage of configuration and key material on the host, and pre-encryption deletion of shadow copies. Early builds showed implementation flaws and immature coding practices, while later versions became more operationally mature.

Nemty was distributed through multiple channels. Reported delivery mechanisms include the RIG exploit kit in malvertising-driven campaigns against systems reliant on outdated browser technologies, malicious spam, compromised or exposed remote desktop services, and delivery by the Trik botnet, also known as Phorpiex. Trik-linked propagation also involved SMB-based spreading using weak credentials. Nemty was additionally advertised in underground forums as a criminal service.

Operationally, Nemty adopted the double-extortion model seen across major ransomware operations, stealing unencrypted data before or alongside encryption and threatening public release if victims refused to pay. This placed it among the earlier ransomware families to combine file encryption with data-leak pressure. Reporting also links Nemty by code lineage or evolution to later ransomware families such as Nefilim and Nokoyawa.

Nemty primarily targets Windows environments and has been observed in both opportunistic and more targeted enterprise-focused intrusion chains.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Persistence
  • Scanning

Operational record

1
YARA rules
3
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Water Roc

Based on our observations on Nefilim attacks to date, our hypothesis is that Nefilim is a RaaS operation whose business model closely resembles that of Nemty, another RaaS operation first spotted in August 2019.

MITRE ATT&CK

Nemty in ATT&CK

34 distinct techniques

Reporting

Research mentioning Nemty

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

May 13
Securelist

Evolution of JSWorm ransomware | Securelist

Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

May 12
Qualys

Nefilim Ransomware: Tactics, Impact, and Mitigation Strategies | Qualys

Feb 23
Trend Micro Research

An Analysis of the Nefilim Ransomware | Trend Micro (US)

Dec 28
Bleeping Computer

Home appliance giant Whirlpool hit in Nefilim ransomware attack

Apr 2
Mcafee Labs

Nemty Ransomware - Learning by Doing | McAfee Blog

Mar 24
Bleeping Computer

Three More Ransomware Families Create Sites to Leak Stolen Data

Mar 23
Trendmicro

Nefilim Ransomware Threatens to Expose Stolen Data | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.