Nemty is a Windows file-encrypting ransomware family first detected in August 2019 and operated as a ransomware-as-a-service offering. It encrypts victim files, changes their extensions, and creates ransom notes directing victims to obtain decryption through an attacker-controlled payment portal. Nemty campaigns adopted double extortion by January 2020, combining encryption with theft of unencrypted data and threats of public disclosure. Early observed infections were concentrated in Korea and China.
Nemty has been distributed through malicious spam carrying archived payloads, RIG exploit-kit malvertising targeting outdated browser and plugin software, and the Trik botnet, also known as Phorpiex. Nemty collects system and network information and uses AES-based file encryption with RSA-protected key material. Its cryptographic implementation changed between versions; some early variants contained weaknesses that enabled recovery without payment. Version 1.6 introduced scheduled-task persistence, terminated applications and stopped services that could interfere with encryption, and deleted shadow copies and backups before encrypting files. Samples have used string obfuscation and third-party packers, including Rex3Packer, to hinder detection and analysis.
Nemty belongs to the ransomware lineage associated with JSWorm. Nefilim shares substantial code with Nemty 2.5 but removed the public ransomware-as-a-service component. These code relationships do not independently establish identical operators across all related families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on our observations on Nefilim attacks to date, our hypothesis is that Nefilim is a RaaS operation whose business model closely resembles that of Nemty, another RaaS operation first spotted in August 2019.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
It is most likely distributed through exposed Remote Desktop Protocol (RDP)... The new ransomware is most likely spread through RDP... Like Nefilim, many of these ransomware attacks abuse exposed RDP ports.
Security researcher Mol69 noticed that the file-encrypting malware is now a payload in malvertising campaigns from RIG exploit kit (EK).
There is evidence of an initial breach via exploitation of vulnerable server-side software (Citrix ADC) and unsecure RDP access.
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
It implements a minor anti-analysis trick consisting of a string obfuscation algorithm. The strings ... are encrypted by the RC4 stream cipher with a hardcoded key “fuckav” and encoded in Base64.
there is no free decryption tool available at the moment and the malware makes sure to remove the file shadows created by Windows.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
Upon launch, the sample will gather the information about storage devices attached to the infected machine, get its external IP address by an HTTP request to http://api.ipify.org
After achieving the privilege level needed, encryption usually occurs on the individual machine without lateral movement
Besides file encryption, it performs actions such as stopping a number of running processes and services to maximize the number of files available for encryption.
In addition, it deletes all system backups, shadow copies, disables the system recovery mode, and clears event logs.
The operators behind Sodinokibi Ransomware have published the download links to archives containing data allegedly stolen from the US firm Kenneth Cole Productions... threatens to leak online the full dump containing stolen data in case the company will decide to not meet the request.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family launched in August 2019 as a public affiliate program and later taken private. The content describes it as code-related to Nefilim/Nephilim and notes later variants using AES-128 and RSA-2048.
The broader ransomware family from which Karma originated and from which Nokoyawa is assessed to have evolved.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a well-known ransomware family linked by similarity to Karma.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.