Description Summary
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artifacts they had seen before in Gandcrab.
Threat Actor
RaaS distributed via RIG exploit kit and the Trik/Phorpiex botnet; artefact overlaps with Sodinokibi and GandCrab.
Technical Indicators
Encryption Extension
.nemty / ._NEMTY_[id]
Encryption Algorithm
AES-128 + RSA-2048 (RC4 in components)
Ransom Note Name
_NEMTY_[id]-DECRYPT.txt
Targeted Industries
Cross-sector
First Seen
September 2019
Last Seen
2020 (evolved into Nefilim)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |