nemty logo

nemty

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Nemty Revenge 2.0, Nefilim, Nemty Project, Nemty Doxware, Nephilim
Ver en IntelTracker → APTTrail →
Nemty emerged in August 2019 as a Ransomware-as-a-Service (RaaS) offering, notably featuring an exclusion mechanism for encrypting systems within specific Commonwealth of Independent States (CIS) countries like Russia, Belarus, Kazakhstan, Tajikistan, and Ukraine. Instead of encryption, it sends system data from these regions back to the operators, suggesting a potential Russian-speaking origin for the group. Initially, Nemty garnered attention due to some artifacts observed in its distribution methods that bore resemblance to Sodinokibi and GandCrab, though direct ties were not definitively established. In April 2020, the Nemty RaaS publicly announced its shutdown, transitioning to a more private and exclusive operational model. This shift followed the release of several decryptors for earlier versions of their ransomware and the emergence of Nefilim ransomware, which shares substantial code with Nemty, indicating a possible acquisition of Nemty's code base rather than a direct evolut

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

ArmeniaAustraliaAzerbaijanBelgiumBelarusChinaGermanyEgyptItalyKyrgyzstan

Sectores objetivo (SOCRadar)

Construction of BuildingsEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionOil & GasAircraft ManufacturingClothing StoresMining

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com