Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors nefilim

Description

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048. Known victims: 15 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Nefilim is a ransomware group identified as a mid-tier criminal threat actor primarily focused on financial gain through targeted ransomware attacks. The group operates with moderate sophistication, leveraging AES-128 encryption protected by RSA2048 for decryption. Nefilim emerged in May 2020 and has demonstrated active operations through September 2021. The group shares code similarities with Nemty but distinguishes itself by removing the Ransom-as-a-Service (RaaS) component, instead relying on direct email communications for payments.

Goals & Targeting

Nefilim's primary motivation is financial gain, achieved through ransomware deployments that encrypt targeted systems and demand payment for decryption keys. The group appears to target a broad range of sectors without specific industry focus, indicating an opportunistic approach rather than sector-specific strategies. Victims are typically organizations with whom the group can extract maximum financial value through encryption while maintaining operational security.

Enhanced Description

Nefilim is a ransomware operation that emerged in mid-2020 and has since been linked to several high-profile incidents. The group primarily targets organizations seeking financial gain through the deployment of ransomware. Nefilim distinguishes itself by its operational approach, which includes direct communication with victims for payment negotiations rather than using a Ransom-as-a-Service (RaaS) infrastructure. The group's ransomware variant shares significant code similarities with Nemty 2.5 but has removed certain components associated with RaaS. Instead of relying on a traditional affiliate program model, Nefilim communicates directly with its victims via email for payment instructions. The group employs AES-128 encryption for data encryption, which is then protected using RSA2048 decryption keys controlled by the attackers. This method ensures that only the victim's decryption key can be provided upon payment of the ransom. Nefilim has demonstrated a focus on financial gain, targeting various industries and sectors without a specific apparent bias. The group's operational timeline places it as an active threat from May 2020 to September 2021, with multiple known victims indicating its persistence in targeting opportunities for profit.

Key Capabilities

  • Ransomware development and deployment
  • Use of AES-128 encryption with RSA2048 protection
  • Direct email communication for payment negotiations
  • Sophisticated encryption mechanisms to control decryption keys

MITRE ATT&CK Tactics

Persistence
Credential Access
Encryption

ATT&CK Techniques

T1059.003 - Powershell command execution via Start-Process Cmd.exe
T1055 - Process injection
T1566.001 - Data Destruction as part of ransomware deployment

Software / Tooling

Nefilim Ransomware (variant of Nemty)
Process injection tools
Email-based communication for payment demands

Campaigns & Victims

Nefilim's campaigns indicate a focus on financial gain with an operational timeline spanning over a year and multiple known victims. The group appears to prioritize targets based on vulnerability rather than sectoral targeting, leveraging organizational weaknesses in cybersecurity to deploy ransomware.

IOC Patterns

  • Ransomware payloads delivered via phishing emails
  • Use of AES-128 encryption with RSA2048 keys
  • Email-based payment communication and negotiation

Recommended Actions

  • Implement robust user training programs to mitigate phishing risks
  • Enhance endpoint detection and response capabilities
  • Regularly back up critical systems and data (air-gapped backups)
  • Monitor for suspicious email activity and encrypted traffic patterns

Suggested Tags

Ransomware
Financial-Crime
Criminal-Group
Encryption-Based-Attack

Confidence Assessment

Moderate confidence in the details provided, with known victims and operational timelines well-documented. Limited information on specific targeting sectors or countries introduces some uncertainty about their full campaign patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Crime
Criminal-Group
Encryption-Based-Attack

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 5, 2020
Last Seen
Sep 9, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.