Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Nefilim

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.

Victims
 

15

First Discovered
victim

2020-05-05

Last Discovered
victim

2021-09-09

Avg Delay
between attack and claim

N/A

Infostealer
for victim with domain

100.0%

View Victims on World Map


Known Locations (1)
Favicon Title Type Available Last Visit FQDN
favicon None No 2025-06-01 21:18:36 hxt254aygrsziejn.onion

Target (Available)
Top 5 Activity Sectors
  • Critical Manufacturing 3
  • Transportation Systems 1
  • Communication 1
Top 5 Countries
  • AU flag Australia 1
  • NZ flag New Zealand 1
  • FR flag France 1
  • DE flag Germany 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Not Available)

No tools used available.


Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (0)

No TTPs available.


Negotiation Chats (0)

No negotiation chats available.


YARA Rules (0)

No YARA rules available.


Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (15)
Logo
Grimmway Farms. Part 1. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
Seven Seas. Part 1. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
Tegut. Part 1. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
TPG Internet. Part 1. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
Saipa Press. Part 1. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
Tegut. Part 2. Nefilim
Discovery Date: 2021-09-09
N/A
Logo
Whirlpool Nefilim
Discovery Date: 2020-12-01
N/A
Logo
Orange (mobile operator) Nefilim
Discovery Date: 2020-07-04
N/A
FR
Logo
Fisher and Paykel Appliances Nefilim
Discovery Date: 2020-06-01
N/A
NZ
Logo
Toll Group Nefilim
Discovery Date: 2020-05-05
N/A
AU