Description Summary
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Threat Actor
Shares code with Nemty 2.5; dropped the RaaS/affiliate model for email-based negotiation. Access via exposed Citrix/RDP.
Technical Indicators
Encryption Extension
.NEFILIM / .NEPHILIM / .OFF
Encryption Algorithm
AES-128 (files) + RSA-2048 (key wrapping)
Ransom Note Name
NEFILIM-DECRYPT.txt
Targeted Industries
Manufacturing, Logistics, Financial
First Seen
March 2020
Last Seen
2021 (actor rebranded, e.g. Karma)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |