Nemty is a Windows ransomware family first observed in 2019 that operated as both a commodity ransomware-as-a-service offering and, later, part of a broader lineage associated with Nefilim and subsequent related families. It encrypts victim files, deletes shadow copies and backups to hinder recovery, drops ransom instructions, and uses Tor-based payment infrastructure in early variants. Multiple reports also associate Nemty with double-extortion behavior beginning in early 2020, in which operators stole unencrypted data and threatened public release to pressure victims into paying.
Nemty was distributed through several channels. High-confidence reporting links it to the RIG exploit kit in malvertising-driven campaigns targeting systems reliant on outdated browser technologies. It was also delivered by the Trik botnet, also known as Phorpiex, to already compromised Windows hosts, and was observed in malicious spam campaigns, particularly in Asia. Some reporting further indicates deployment through compromised or exposed Remote Desktop services. These varied delivery paths are consistent with Nemty’s role as an affiliate-driven ransomware operation.
Technically, Nemty evolved rapidly across versions. Analyses describe file encryption using AES combined with RSA, including AES-128-CBC and RSA-2048 in some variants, while early samples also used an embedded RSA-8192 public key to protect victim configuration data. Later versions improved operational behavior by stopping services and applications that could lock files, establishing persistence via scheduled tasks, and moving shadow-copy deletion earlier in the execution chain. Researchers noted coding immaturity and cryptographic implementation issues in some early builds, but the malware remained capable of rendering files inaccessible and demanding payment.
Nemty operators and related reporting indicate overlap in tooling, packers, and lineage with other ransomware families including Sodinokibi, Nefilim, Karma, and Nokoyawa. Nefilim is widely assessed as derived from Nemty code after the operators abandoned the public RaaS model and shifted toward more targeted intrusions. Nemty activity has been observed globally, with notable reporting on infections in Korea and China, and its later extortion model aligns with the broader trend of enterprise-focused ransomware operations combining encryption with data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on our observations on Nefilim attacks to date, our hypothesis is that Nefilim is a RaaS operation whose business model closely resembles that of Nemty, another RaaS operation first spotted in August 2019.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
It is most likely distributed through exposed Remote Desktop Protocol (RDP)... The new ransomware is most likely spread through RDP... Like Nefilim, many of these ransomware attacks abuse exposed RDP ports.
Security researcher Mol69 noticed that the file-encrypting malware is now a payload in malvertising campaigns from RIG exploit kit (EK).
There is evidence of an initial breach via exploitation of vulnerable server-side software (Citrix ADC) and unsecure RDP access.
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
Nemty 1.6 gains persistence by adding a scheduled task using the following command: cmd.exe /c schtasks.exe /create /sc onstart /tn “NEMTY_<FILEID>_” /tr “C:\Users\user\AdobeUpdate.exe”
It implements a minor anti-analysis trick consisting of a string obfuscation algorithm. The strings ... are encrypted by the RC4 stream cipher with a hardcoded key “fuckav” and encoded in Base64.
there is no free decryption tool available at the moment and the malware makes sure to remove the file shadows created by Windows.
Compared to phishing email, which is currently the common distribution method, leveraging a RDP connection puts the attacker in control... Once attackers have valid credentials, only 37% of their actions are blocked
Upon launch, the sample will gather the information about storage devices attached to the infected machine, get its external IP address by an HTTP request to http://api.ipify.org
After achieving the privilege level needed, encryption usually occurs on the individual machine without lateral movement
Besides file encryption, it performs actions such as stopping a number of running processes and services to maximize the number of files available for encryption.
In addition, it deletes all system backups, shadow copies, disables the system recovery mode, and clears event logs.
The operators behind Sodinokibi Ransomware have published the download links to archives containing data allegedly stolen from the US firm Kenneth Cole Productions... threatens to leak online the full dump containing stolen data in case the company will decide to not meet the request.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family launched in August 2019 as a public affiliate program and later taken private. The content describes it as code-related to Nefilim/Nephilim and notes later variants using AES-128 and RSA-2048.
The broader ransomware family from which Karma originated and from which Nokoyawa is assessed to have evolved.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a well-known ransomware family linked by similarity to Karma.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.