Nemty Ransomware

Description Summary

Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artifacts they had seen before in Gandcrab.

Threat Actor

RaaS distributed via RIG exploit kit and the Trik/Phorpiex botnet; artefact overlaps with Sodinokibi and GandCrab.

Technical Indicators

Encryption Extension
.nemty / ._NEMTY_[id]
Encryption Algorithm
AES-128 + RSA-2048 (RC4 in components)
Ransom Note Name
_NEMTY_[id]-DECRYPT.txt
Targeted Industries
Cross-sector
First Seen
September 2019
Last Seen
2020 (evolved into Nefilim)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts