Nefilim Ransomware

Description Summary

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.

Threat Actor

Shares code with Nemty 2.5; dropped the RaaS/affiliate model for email-based negotiation. Access via exposed Citrix/RDP.

Technical Indicators

Encryption Extension
.NEFILIM / .NEPHILIM / .OFF
Encryption Algorithm
AES-128 (files) + RSA-2048 (key wrapping)
Ransom Note Name
NEFILIM-DECRYPT.txt
Targeted Industries
Manufacturing, Logistics, Financial
First Seen
March 2020
Last Seen
2021 (actor rebranded, e.g. Karma)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts