Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors nokoyawa

Description

Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252). Known victims: 36 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Nokoyawa is a medium-sophistication criminal threat actor specializing in double extortion ransomware. They gained notoriety by exploiting the Windows CLFS zero-day (CVE-2023-28252) and operating a Ransomware as a Service (RaaS) program under 'farnetwork'. Primarily targeting South American businesses across healthcare, finance, government, and manufacturing sectors, they have shown significant campaign activity between 2022 and 2023.

Goals & Targeting

Nokoyawa's primary goals are financial gain through ransom payments and organizational disruption. They specifically target sectors with deep financial resources and sensitive data, primarily in South American countries, where they may find lower defenses and higher success rates for extortion attempts. Their targeting indicates a focus on industries that can afford to pay ransoms without immediate public backlash, such as healthcare and financial services.

Enhanced Description

Nokoyawa is a double extortion ransomware group that emerged in late 2022 with the launch of their Ransomware as a Service (RaaS) program operated by 'farnetwork'. Known for their aggressive targeting of South American businesses, particularly those in healthcare, financial services, government, and manufacturing, Nokoyawa has executed numerous successful ransomware campaigns. They achieved significant prominence in 2023 through the exploitation of a critical Windows Common Log File System (CLFS) zero-day vulnerability (CVE-2023-28252), which allowed them to infiltrate high-value targets with relative ease. Nokoyawa's operations are characterized by double extortion tactics, where they demand ransom for both decrypted data and the return of stolen information. This approach has made them a formidable adversary in the cybercrime landscape.

Key Capabilities

  • Double extortion
  • Ransomware deployment
  • Exploitation of zero-day vulnerabilities (CVE-2023-28252)
  • RaaS operations

MITRE ATT&CK Tactics

Data Destruction
Exploitation for Access
Encryption of Data on Devices

ATT&CK Techniques

T1078.004
T1059.015
T1203.001
T1485.001

Software / Tooling

Ransomware (double extortion variant)
Exploit code targeting CVE-2023-28252

Campaigns & Victims

Nokoyawa has demonstrated a steady operational tempo, with campaigns primarily launching in South America. Their use of a RaaS model suggests an ability to scale their operations by outsourcing attacks to other operators, while the exploitation of a zero-day indicates moderate to high sophistication levels in their tradecraft. Notable past operations include incidents targeting healthcare providers and financial institutions, where successful compromises have led to significant financial payouts.

IOC Patterns

  • Double extortion emails
  • Network traffic indicative of ransomware C2 servers
  • Exploitation attempts exploiting CVE-2023-28252
  • Encrypted files with specific extension patterns

Recommended Actions

  • Enhance network perimeter defenses to prevent exploit-based intrusions.
  • Implement rigorous backup and recovery solutions to mitigate ransomware impacts.
  • Monitor for T1059 activity indicative of initial access via phishing or exploited vulnerabilities.

Suggested Tags

Ransomware
Double Extortion
Financial Crime
South America

Confidence Assessment

Confidence in nokoyawa's profile is high based on the detailed description and known victims. However, gaps exist regarding specific campaign details beyond general targeting patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Zero-Day Exploitation
Government Targeting
Double Extortion
Financial Crime
South America

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 9, 2022
Last Seen
Aug 4, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.