Nephilim is a human-operated ransomware family that emerged in March 2020 and is closely related to NEMTY, sharing a substantial portion of its codebase. It is generally assessed to be an evolution or fork derived from NEMTY rather than a continuation of the same public ransomware-as-a-service operation. Unlike NEMTY’s earlier portal-based model, Nephilim used direct email-based victim communications and was associated with a double-extortion scheme in which operators stole sensitive data before encryption and threatened public release if victims refused to pay or attempted to negotiate.
Nephilim intrusions were commonly associated with exploitation of vulnerable Remote Desktop Protocol services for initial access. After gaining access, operators established persistence, sought additional credentials, conducted post-compromise activity, exfiltrated data, and then deployed the ransomware payload across intended targets. The malware encrypts files with AES-128 and protects the per-file encryption keys with an embedded RSA-2048 public key. No reliable public decryption weakness is known, and recovery without attacker cooperation has not been established.
Affected files are renamed with Nephilim-related extensions, and ransom notes are dropped on compromised systems. Some campaigns also changed the victim desktop wallpaper as part of the extortion workflow. Nephilim maintained both clearnet and Tor-based leak infrastructure to publish stolen corporate data, making it part of the broader wave of ransomware operations that normalized data-theft-backed extortion against enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family that encrypts files and extorts victims, including threatening to publish stolen sensitive data if victims do not pay. It is delivered primarily through vulnerable RDP services, uses AES-128 and RSA-2048 for encryption, drops ransom notes, changes desktop wallpaper, and appends .Nefilim or .NEPHILIM to encrypted files.
Ransomware operation mentioned only as part of a list of groups using data leak sites or stolen data for extortion.
Named as another ransomware operation that steals unencrypted files for extortion.
Private RaaS formed by the Nemty operator by recruiting experienced affiliates; uses a leak site for extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.