nefilim logo

nefilim

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Nephilim, Nemty
Ver en IntelTracker → APTTrail →
Nefilim, also known as Nephilim, emerged in early 2020 as a ransomware group specializing in double extortion, a tactic involving both file encryption and data exfiltration with threats to publish stolen information. This group evolved from the Nemty ransomware family, adopting and modifying its codebase while discontinuing the Ransomware-as-a-Service model to focus on more targeted attacks and direct email communication for ransom negotiations. Nefilim distinguishes itself by primarily targeting high-revenue organizations, often with annual revenues exceeding $100 million, and employs tailored ransom demands to maximize financial gain. The group's primary motivation is financial, achieved by pressuring victims through data exposure on dedicated leak sites if ransoms are not paid.
Tecnicas MITRE
T1566.001, T1078.002, T1486, T1047, T1071.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

AustraliaBelgiumBrazilCanadaSwitzerlandChinaGermanyEgyptFranceIndia

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com