Nefilim — Ransomware Profile
Nefilim was a ransomware-as-a-service operation first documented in March 2020, when SentinelLabs analysed it and found it shared a substantial portion of its code with the earlier Nemty family. Affiliates typically broke in through exposed Remote Desktop Protocol or unpatched Citrix remote-access products, with reported abuse of Citrix flaws CVE-2019-11634 and CVE-2019-19781 for initial access. The crew ran a double-extortion model, stealing data before encryption and threatening to publish it on "Corporate Leaks" sites run by the administrators. Trend Micro, which tracks the operators as Water Roc, reported that Nefilim went after multi-billion-dollar companies in North and South America across finance, manufacturing and transportation; the US Justice Department separately described administrators as preferring targets in the United States, Canada or Australia with annual revenue above $100 million, and alleged that they granted affiliates access in exchange for 20 percent of ransom proceeds. US prosecutors allege that Volodymyr Tymoshchuk was one of the Nefilim administrators from July 2020 through October 2021, and Group-IB assesses that Karma, discovered in June 2021, is the successor version of Nefilim. The brand is no longer known to be operating, and US prosecutors have since charged an administrator and secured a guilty plea from a Ukrainian affiliate.Also tracked as
Nephilim, Water Roc
Vendor research
- Meet NEMTY Successor, Nefilim/Nephilim Ransomware SentinelOne (SentinelLabs)
- Nefilim Ransomware Attack Through a MITRE Att&ck Lens Trend Micro
- Ransomware manager: Investigation into farnetwork, a threat actor behind the Nokoyawa RaaS program Group-IB
- Ukrainian National Pleads Guilty to Conspiracy to Use Nefilim Ransomware to Attack Companies in the United States and Other Countries U.S. Department of Justice