Nefilim is a Windows ransomware family first observed in early 2020 and widely assessed as closely related to, or evolved from, Nemty. It became known for double-extortion operations in which attackers exfiltrate sensitive data before encrypting systems and then threaten public disclosure if the victim refuses to pay. The group operated a leak site branded as Corporate Leaks and targeted large organizations, including enterprises in sectors such as manufacturing, logistics, transportation, education, and other high-revenue businesses.
Nefilim commonly gained initial access through exposed or brute-forced Remote Desktop Protocol services and through exploitation of vulnerable Citrix remote-access infrastructure, including CVE-2019-19781 and CVE-2019-11634. Post-compromise activity included credential theft, Active Directory reconnaissance, lateral movement, process and service termination, data staging, exfiltration, and final ransomware deployment. Reported tooling associated with Nefilim intrusions includes Mimikatz, LaZagne, NetPass, AdFind, BloodHound, PsExec, Windows Management Instrumentation, Process Hacker, PC Hunter, Revo Uninstaller, 7-Zip, Cobalt Strike, and MEGAsync. These tools were used to harvest credentials, enumerate domain assets, move across the network, disable defenses, compress stolen data, and transfer it out of the environment.
The ransomware encrypts files with AES-128 and protects the per-file AES material with an embedded RSA-2048 public key. Encrypted files are renamed with a Nefilim-specific extension, and the malware drops a ransom note instructing victims to negotiate over email rather than through a dedicated payment portal. Analyses also noted anti-debugging checks and self-deletion behavior. Nefilim is associated with a shift away from a public ransomware-as-a-service model toward more targeted intrusions and private affiliate or operator-led activity. It is part of the broader JSWorm/Nemty lineage that underwent multiple rebrands and operational changes while retaining overlapping code, cryptographic design, and extortion practices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
Nefilim targets vulnerabilities such as CVE-2019-11634 and CVE-2019-19781 in Citrix gateway devices, identified in December 2019 and patched in January 2020. | One of the more popular ransomware families over the last few months to switch to this extortion tactic was Nefilim. Nefilim ransomware emerged in March 2020 when Nemty operators quit the ransomware as a service model to concentrate their energy on more targeted attacks with more focused resources.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
To better describe this new wave of ransomware, we present an in-depth case study of the Nefilim ransomware family. Nefilim has been known to target mainly multi-billion dollar companies...
Home appliances giant Whirlpool suffered a ransomware attack by the Nefilim ransomware gang who stole data before encrypting devices.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Nefilim has been observed to use a batch file for terminating certain processes and services.
AdFind can be used to discover computers, users, or groups with AD as a reconnaissance tool...
cybercriminals have weaponized this function for ransomware campaigns to discover and terminate arbitrary processes and services, including those that are antimalware-related.
As Process Hacker can be used to gain an overview of processes currently being used...
MEGA and MegaSync can be used for data exfiltration — a vital step for recent ransomware campaigns that wield the double extortion technique...
The FBI, CISA, and MS-ISAC have received numerous reports of ransomware attacks against K-12 educational institutions. | malicious cyber actors target school computer systems, slowing access, and—in some instances—rendering the systems inaccessible for basic functions, including distance learning.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a permutation of the JSWorm ransomware family in similarity analysis involving Karma.
Ransomware family mentioned only in a related-article link title; no operational details provided in the main content.
Ransomware used in an intrusion that leveraged credentials of a deceased employee.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.