Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252). Known victims: 36 2 ransom note(s) on file
Objectives
Executive Summary
Nokoyawa is a medium-sophistication criminal threat actor specializing in double extortion ransomware. They gained notoriety by exploiting the Windows CLFS zero-day (CVE-2023-28252) and operating a Ransomware as a Service (RaaS) program under 'farnetwork'. Primarily targeting South American businesses across healthcare, finance, government, and manufacturing sectors, they have shown significant campaign activity between 2022 and 2023.
Goals & Targeting
Nokoyawa's primary goals are financial gain through ransom payments and organizational disruption. They specifically target sectors with deep financial resources and sensitive data, primarily in South American countries, where they may find lower defenses and higher success rates for extortion attempts. Their targeting indicates a focus on industries that can afford to pay ransoms without immediate public backlash, such as healthcare and financial services.
Enhanced Description
Nokoyawa is a double extortion ransomware group that emerged in late 2022 with the launch of their Ransomware as a Service (RaaS) program operated by 'farnetwork'. Known for their aggressive targeting of South American businesses, particularly those in healthcare, financial services, government, and manufacturing, Nokoyawa has executed numerous successful ransomware campaigns. They achieved significant prominence in 2023 through the exploitation of a critical Windows Common Log File System (CLFS) zero-day vulnerability (CVE-2023-28252), which allowed them to infiltrate high-value targets with relative ease. Nokoyawa's operations are characterized by double extortion tactics, where they demand ransom for both decrypted data and the return of stolen information. This approach has made them a formidable adversary in the cybercrime landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nokoyawa has demonstrated a steady operational tempo, with campaigns primarily launching in South America. Their use of a RaaS model suggests an ability to scale their operations by outsourcing attacks to other operators, while the exploitation of a zero-day indicates moderate to high sophistication levels in their tradecraft. Notable past operations include incidents targeting healthcare providers and financial institutions, where successful compromises have led to significant financial payouts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in nokoyawa's profile is high based on the detailed description and known victims. However, gaps exist regarding specific campaign details beyond general targeting patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics