Nefilim — Ransomware Profile

Nefilim was a ransomware-as-a-service operation first documented in March 2020, when SentinelLabs analysed it and found it shared a substantial portion of its code with the earlier Nemty family. Affiliates typically broke in through exposed Remote Desktop Protocol or unpatched Citrix remote-access products, with reported abuse of Citrix flaws CVE-2019-11634 and CVE-2019-19781 for initial access. The crew ran a double-extortion model, stealing data before encryption and threatening to publish it on "Corporate Leaks" sites run by the administrators. Trend Micro, which tracks the operators as Water Roc, reported that Nefilim went after multi-billion-dollar companies in North and South America across finance, manufacturing and transportation; the US Justice Department separately described administrators as preferring targets in the United States, Canada or Australia with annual revenue above $100 million, and alleged that they granted affiliates access in exchange for 20 percent of ransom proceeds. US prosecutors allege that Volodymyr Tymoshchuk was one of the Nefilim administrators from July 2020 through October 2021, and Group-IB assesses that Karma, discovered in June 2021, is the successor version of Nefilim. The brand is no longer known to be operating, and US prosecutors have since charged an administrator and secured a guilty plea from a Ukrainian affiliate.

Also tracked as

Nephilim, Water Roc

Vendor research

Read the full analysis on IntelFusions