Nefilim

Aliases: Nephilim

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-10 00:11:47
Profile updated
2026-07-07 12:38:12

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications transportation-and-logistics

Context

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.

Detection coverage

  • 5 YARA rules

Detection rules

  • TRELLIX_ARC_Nefilim_Ransomware (yara-rule)
  • TRELLIX_ARC_Nefilim_Signed (yara-rule)
  • TRELLIX_ARC_RANSOM_Nefilim_Go (yara-rule)
  • DITEKSHEN_MALWARE_Win_Nemty (yara-rule)
  • MALPEDIA_Win_Nefilim_Auto (yara-rule)

Related threat objects

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • secureworks.com — Gold Mansard (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • CISA — Aa20 345A (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • accenture.com — Evolving Danger Ransomware Extortion (report)
  • blackberry.com — Wp Spark State Of Ransomware (report)
  • bleepingcomputer.com — Three More Ransomware Families Create Sites To Leak Stolen Data (report)
  • hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)
  • Trend Micro — Ransomware As A Service Enabler Of Widespread Attacks (report)
  • labs.sentinelone.com — Meet Nemty Successor Nefilim Nephilim Ransomware (report)
  • Kaspersky — 102428 (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • zdnet.com — A Deep Dive Into Nefilim A Double Extortion Ransomware Group (report)
  • Trend Micro — Nefilim Modern Ransomware Attack Story (report)
  • blog.qualys.com — Nefilim Ransomware (report)
  • Trend Micro — Wp Modern Ransomwares Double Extortion Tactics (report)
  • id-ransomware.blogspot.com — Nefilim Ransomware (report)
  • intel471.com — How Cybercriminals Create Turbulence For The Transportation Industry (report)
  • news.sophos.com — Nefilim Ransomware Attack Uses Ghost Credentials (report)
  • bleepingcomputer.com — Home Appliance Giant Whirlpool Hit In Nefilim Ransomware Attack (report)
  • bleepingcomputer.com — New Nefilim Ransomware Threatens To Release Victims Data (report)

External references