Nefilim
Ransomware Group Profile
Overview
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Dark Web Infrastructure (1)
hxt254aygrsziejn.onion
Associated Threat Actors (1)
Activity Timeline
First Seen2021
Last Seen2021
Leak Sites1
Quick Actions