According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048. Known victims: 15 1 ransom note(s) on file
Objectives
Executive Summary
Nefilim is a ransomware group identified as a mid-tier criminal threat actor primarily focused on financial gain through targeted ransomware attacks. The group operates with moderate sophistication, leveraging AES-128 encryption protected by RSA2048 for decryption. Nefilim emerged in May 2020 and has demonstrated active operations through September 2021. The group shares code similarities with Nemty but distinguishes itself by removing the Ransom-as-a-Service (RaaS) component, instead relying on direct email communications for payments.
Goals & Targeting
Nefilim's primary motivation is financial gain, achieved through ransomware deployments that encrypt targeted systems and demand payment for decryption keys. The group appears to target a broad range of sectors without specific industry focus, indicating an opportunistic approach rather than sector-specific strategies. Victims are typically organizations with whom the group can extract maximum financial value through encryption while maintaining operational security.
Enhanced Description
Nefilim is a ransomware operation that emerged in mid-2020 and has since been linked to several high-profile incidents. The group primarily targets organizations seeking financial gain through the deployment of ransomware. Nefilim distinguishes itself by its operational approach, which includes direct communication with victims for payment negotiations rather than using a Ransom-as-a-Service (RaaS) infrastructure. The group's ransomware variant shares significant code similarities with Nemty 2.5 but has removed certain components associated with RaaS. Instead of relying on a traditional affiliate program model, Nefilim communicates directly with its victims via email for payment instructions. The group employs AES-128 encryption for data encryption, which is then protected using RSA2048 decryption keys controlled by the attackers. This method ensures that only the victim's decryption key can be provided upon payment of the ransom. Nefilim has demonstrated a focus on financial gain, targeting various industries and sectors without a specific apparent bias. The group's operational timeline places it as an active threat from May 2020 to September 2021, with multiple known victims indicating its persistence in targeting opportunities for profit.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nefilim's campaigns indicate a focus on financial gain with an operational timeline spanning over a year and multiple known victims. The group appears to prioritize targets based on vulnerability rather than sectoral targeting, leveraging organizational weaknesses in cybersecurity to deploy ransomware.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the details provided, with known victims and operational timelines well-documented. Limited information on specific targeting sectors or countries introduces some uncertainty about their full campaign patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics