Ransomware Group:  
Nefilim



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | Ransom Note(s) | Activity | Worldmap | Victims (15)

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.


Sites

Title Available Last Visit FQDN Screenshot
None 🔴 2021-05-01 00:00:00.000000 hxt254aygrsziejn.onion N/A

Ransom Note(s)

Activity over time

Worldmap

15 Victims

 flag

Atlanta Allergy & Asthma. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Grimmway Farms. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Elliott Group / Cascade Engineering / Unitex Textile Rental Services. Teaser. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Seven Seas. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

The MADSACK Media Group. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Tegut. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

TPG Internet. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Saipa Press. Part 1. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Tegut. Part 2. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

The MADSACK Media Group. Part 2. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Whirlpool 

Company logo
Ransomware Group:

Discovery Date: 2020-12-01 00:00

Group: 
DE flag

DKA (refrigeration and air conditioning specialist, Dussmann Group subsidiary) 

Company logo
Ransomware Group:

Discovery Date: 2020-07-27 00:00

Group: 
FR flag

Orange (mobile operator) 

Company logo
Ransomware Group:

Discovery Date: 2020-07-04 00:00

Group: 
NZ flag

Fisher and Paykel Appliances 

Company logo
Ransomware Group:

Discovery Date: 2020-06-01 00:00

Group: 
AU flag

Toll Group 

Company logo
Ransomware Group:

Discovery Date: 2020-05-05 00:00

Group: