Discovery Enum
- AdFind
- SoftPerfect NetScan
Nokoyawa is a human-operated ransomware family used in ransomware-as-a-service and affiliate-driven intrusions.
Profile source: Mallory opens in a new tabNokoyawa
Nokoyawa is a human-operated ransomware family used in ransomware-as-a-service and affiliate-driven intrusions. It has been associated with financially motivated cybercrime activity and has been linked in reporting to operators and personas connected with other ransomware operations including Nemty, Karma, JSWORM, and Nefilim. Microsoft has also observed the affiliate cluster DEV-0237 deploying Nokoyawa during 2022 after previously using other ransomware payloads, underscoring the fluid relationship between access brokers, distributors, and ransomware affiliates.
Observed Nokoyawa intrusions show rapid progression from initial compromise to domain-wide encryption. In one documented case, the infection chain began with thread-hijacked phishing emails delivering an HTML smuggling lure that led to IcedID execution, followed by Cobalt Strike-enabled hands-on-keyboard activity and ransomware deployment roughly 12 hours after initial infection. Operators performed host and domain discovery, accessed credential material from LSASS, used Active Directory reconnaissance tooling, recovered saved remote-session credentials, and moved laterally with valid accounts over RDP. Ransomware staging and execution across multiple hosts used administrative mechanisms including SMB, WMIC, and PsExec, with remote service creation to run the payload as SYSTEM.
Nokoyawa’s encryption behavior includes targeting local and network-accessible resources, loading hidden drives, and deleting volume shadow copies to inhibit recovery. Reported configurations excluded common system directories and selected file types to preserve operating system stability while maximizing business impact. The malware is therefore best understood as the final payload in broader post-compromise operations that combine credential access, reconnaissance, lateral movement, and enterprise-wide deployment.
Nokoyawa has also been cited in overlap analyses comparing tradecraft among major ransomware operations, suggesting shared operators, affiliates, or development lineage within the broader cybercriminal ecosystem. It primarily targets Windows enterprise environments in observed reporting.
Reported operators
In May 2022, DEV-0237 started to routinely deploy Nokoyawa, a payload that we observed the group previously experimenting with when they weren’t using Hive.
Five minutes after transferring the files to hosts in the domain, the Nokoyawa ransomware binary was executed on a domain controller... The time to ransomware (TTR) was just over 12 hours from the initial infection.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.