Nokoyawa is a ransomware family targeting 64-bit Windows systems that emerged in February 2022. Its code lineage traces through Karma to Nemty. Operators use it in double-extortion attacks, stealing sensitive organizational data before encrypting files and threatening publication unless a ransom is paid. Early targeting concentrated on South America, particularly Argentina; subsequent campaigns affected small and medium-sized businesses in the Middle East, North America, and Asia.
Early versions were written in C/C++ and combined SECT233R1 elliptic-curve cryptography with Salsa20. Nokoyawa 2.0, introduced in September 2022, was rewritten in Rust and uses Curve25519 with Salsa20. It partially encrypts larger files to improve speed and supports configurable ransom notes, encryption parameters, exclusions, network-share encryption, and access to hidden drives. Analyzed variants delete Windows volume shadow copies through a DeviceIoControl operation to inhibit recovery. Version 1.1 supports encryption in Safe Mode and runtime API-name resolution using hashes. Rust-based variants apply language-based exclusions intended to avoid CIS-region systems. The closely related Nevada variant, designated version 2.1, adds self-deletion after encryption.
Nokoyawa has been deployed by affiliates including DEV-0237 and ShadowSyndicate, with a documented intrusion attributed to Storm-0390/Periwinkle Tempest. Infection chains have begun with thread-hijacked phishing emails delivering IcedID through HTML smuggling, followed by Cobalt Strike and hands-on network compromise. Operators have used PsExec and WMIC for ransomware deployment and exploited Windows Common Log File System vulnerabilities for privilege escalation, including CVE-2023-28252 before its April 2023 patch. Operational overlap with Hive does not establish shared malware code or a rebranding relationship.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
April 2023 brought a patch for yet another CLFS zero-day – CVE-2023-28252. ... On Patch Tuesday in April 2023, we published a brief report about Nokoyawa ransomware attacks using this zero-day, as well as details about the exploit itself.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
Like CVE-2023-28252, three of these earlier vulnerabilities used to deliver Nokoyawa (CVE-2022-24521, CVE-2022-37969, and CVE-2023-23376) were zero-days detected in the wild. | ...a series of attempts to exploit similar vulnerabilities intended to culminate in the deployment of the Nokoyawa strain of ransomware.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nokoyawa ransomware campaigns occurred in October 2022, November 2022, and March 2023.
CVE-2023-28252 is actively exploited in the wild by cybercriminals to escalate privileges and deploy the Nokoyawa ransomware payload.
In May 2022, DEV-0237 started to routinely deploy Nokoyawa, a payload that we observed the group previously experimenting with when they weren’t using Hive.
Five minutes after transferring the files to hosts in the domain, the Nokoyawa ransomware binary was executed on a domain controller... The time to ransomware (TTR) was just over 12 hours from the initial infection.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft disclosed a zero-day vulnerability in the Windows Common Log File System (CLFS), which cybercriminals are actively exploiting to deploy Nokoyawa ransomware payloads. The vulnerability, tracked as CVE-2023-28252 ... is a Privilege Escalation vulnerability in the Windows Common Log File System Driver ... Successful exploitation enables threat actors to gain SYSTEM privileges
In addition, Nokoyawa 1.1 is the only variant that obfuscates the Windows API functions that are called during runtime by resolving each name via CRC32 hash.
In order to reduce the risk of law enforcement actions, Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID... and the latter calls GetUserDefaultUILanguage... to determine the system's locale and language, respectively.
Nokoyawa 1.1 also has a --safe-mode command-line option to reboot the system into Windows safe mode prior to file encryption to maximize the number of files that can be encrypted by loading the minimal set of applications, and therefore, minimize the number of open file handles that may interfere with encryption.
The configuration parameter is a Base64 encoded JSON object that has the following keys and values shown in Table 2... ENCRYPT_NETWORK Encrypt network shares
In order to reduce the risk of law enforcement actions, Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID... and the latter calls GetUserDefaultUILanguage... to determine the system's locale and language, respectively.
Both Nokoyawa 2.0 and Nevada check whether the infected system is located in a former Commonwealth of Independent States (CIS) country. The former calls the Windows API GetSystemDefaultLCID for language IDs ... and the latter calls GetUserDefaultUILanguage ... to determine the system's locale and language, respectively.
After exploitation, attackers must still establish command and control (C2) communications before finally delivering and deploying the Nokoyawa strain of ransomware. The report provides additional indicators of compromise (IoCs) related to these and other stages of the campaign, including the Cobalt Strike Beacon domains used for C2.
Threat actors deploying Nokoyawa ransomware are known to employ the double extortion technique, where data is exfiltrated prior to ransomware deployment | Microsoft disclosed a zero-day vulnerability in the Windows Common Log File System (CLFS), which cybercriminals are actively exploiting to deploy Nokoyawa ransomware payloads.
There are a few commonalities between all Nokoyawa variants such as being compiled only for 64-bit versions of Windows and using a relatively obscure method to delete Windows Shadow Copies. The latter entails calling the function DeviceIoControl ... with the undocumented control code parameter IOCTL_VOLSNAP_SET_MAX_DIFF_AREA_SIZE (0x53C028) with a maximum size of 1, which causes Windows to delete all shadow copies as a result.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family with strong TTP and possible personnel overlap with Play.
A ransomware family assessed as an evolution of the Nemty strain Karma. It encrypts local files and optionally network shares, excludes certain folders and extensions, uses dynamically loaded bcrypt.dll with BCryptGenRandom to seed an ephemeral Sect233r1 key pair, derives a shared Salsa20 key for file encryption, appends its ransomware extension, and drops a ransom note threatening data leakage.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Ransomware payload delivered after exploitation of CLFS privilege-escalation vulnerabilities; the campaign discussed was intended to culminate in Nokoyawa deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.