Nemim

Aliases: Nemain

First seen
2018-07-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-15 16:45:04
Profile updated
2026-07-07 12:35:37

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:ru country_code:fr country_code:us

Context

Nemim, also known as Nemain, is a Remote Access Trojan (RAT) used primarily for cyber espionage. It has been observed targeting government, financial, and technology sectors in various countries, including Russia, France, and the United States.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Nemim_Auto (yara-rule)

Reports & references

  • secureworks.com — Tungsten Bridge (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nemim (report)
  • blog.nsfocus.net — Darkhotel 3 0908 (report)

External references