Skip to content

Nokoyawa

Nokoyawa is a Windows ransomware family that emerged in early 2022 and is associated with double-extortion operations in which attackers steal data before encrypting systems and demanding payment.

Profile source: Mallory opens in a new tab

Nokoyawa

Family profile

Nokoyawa is a Windows ransomware family that emerged in early 2022 and is associated with double-extortion operations in which attackers steal data before encrypting systems and demanding payment. It is widely assessed as part of the Nemty/Karma lineage, although some reporting has also noted operational overlap with Hive and other ransomware ecosystems, likely reflecting shared affiliates or infrastructure rather than a direct code relationship in all cases. The malware has been linked to hands-on-keyboard intrusions conducted by ransomware affiliates and has appeared in campaigns culminating after earlier-stage infections involving commodity malware and Cobalt Strike.

Nokoyawa targets 64-bit Windows systems and has evolved through multiple versions, including variants commonly labeled 1.0, 1.1, 2.0, and 2.1, with the latter also referred to as Nevada. Earlier variants were written in C or C++, while later versions were rewritten in Rust. Across versions, Nokoyawa uses elliptic-curve cryptography combined with Salsa20 for file encryption, with later variants moving from SECT233R1 to Curve25519/X25519-based key exchange. The malware supports configurable execution through command-line parameters and, in some versions, a Base64-encoded JSON configuration that allows operators or affiliates to customize ransom-note content, encrypted-file extensions, skip lists, network-encryption behavior, hidden-drive handling, and shadow-copy deletion.

The ransomware is designed for rapid enterprise-wide impact. Observed capabilities include encryption of local files, optional encryption of network shares, deletion of Windows Shadow Copies, exclusion logic for selected directories and file types, and in some variants self-deletion after execution. One analyzed variant supports rebooting a host into Safe Mode before encryption. Nokoyawa has also been observed using locale-based checks to avoid execution on systems associated with former CIS countries. In intrusion reporting, operators deployed the ransomware after credential theft, Active Directory reconnaissance, lateral movement, and staging across multiple hosts, including domain controllers and servers.

Nokoyawa has been associated with exploitation chains involving Windows Common Log File System privilege-escalation vulnerabilities, including multiple CLFS zero-days used after initial compromise to elevate privileges before ransomware deployment. It has also been observed at the end of phishing-led intrusions in which initial access malware established persistence and command-and-control before operators moved laterally and launched the encryptor. Reported victimology includes organizations in South America, especially Argentina, as well as small and medium businesses in the Middle East, North America, and Asia. Repeated overlap in leak-site victim postings with other ransomware brands has also been noted.

The family is notable both for its technical evolution and for its place in the broader ransomware-as-a-service ecosystem, where affiliates, access brokers, and shared tooling blur boundaries between nominally distinct ransomware brands. Nokoyawa remains best characterized as a Windows ransomware family used in human-operated intrusions that combine data theft, lateral movement, and file encryption for extortion.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Privilege Escalation

Operational record

1
YARA rules
2
Ransom notes
4
Leak sites
0 available

Discovery Enum

  • AdFind
  • SoftPerfect NetScan

Exfiltration

  • FileZilla

LOLBAS

  • PsExec

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk

Reported operators

Threat actors

3 named in public reporting
Karma

CLFSの脆弱性を悪用して特権昇格を行った攻撃グループは、最終的にNokoyawaランサムウェアを投下しようとしたことが確認されています。

WIZARD SPIDER

In May 2022, DEV-0237 started to routinely deploy Nokoyawa, a payload that we observed the group previously experimenting with when they weren’t using Hive.

Storm-0390

Five minutes after transferring the files to hosts in the domain, the Nokoyawa ransomware binary was executed on a domain controller... The time to ransomware (TTR) was just over 12 hours from the initial infection.

Exploited software

Vulnerabilities linked to Nokoyawa

4 CVEs

MITRE ATT&CK

Nokoyawa in ATT&CK

19 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.