nokoyawa logo

nokoyawa

1 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Nokoyawa is a financially motivated ransomware group that first emerged in February 2022, initially demonstrating code similarities with Nemty and Karma ransomware families and reusing functions from the leaked Babuk source code. While early reports mistakenly associated it with Hive ransomware, later analysis confirmed its distinct lineage. The group sets itself apart by employing a unique Elliptic Curve Cryptography (ECC) routine, specifically SECT233R1 and Curve25519 with Salsa20 for file encryption. In September 2022, Nokoyawa evolved significantly, being rewritten in the Rust programming language as Nokoyawa 2.0, enhancing its encryption capabilities and operational flexibility, notably through a command-line configurable JSON object. The group is known to operate under variants such as Nokoyawa 1.1, Nokoyawa 2.0, and Nevada (Nokoyawa 2.1), and has shown connections with the Snatch ransomware group through shared victims on data leak sites.
Malware asociado
XOR.DDoS, Arkei, OSX_OCEANLOTUS.D, win.daxin, win.emotet, Backdoor.Oldrea
Tecnicas MITRE
T1490, T1070, T1482, T1090, T1486, T1497
CVEs relacionadas
CVE-2023-29324, CVE-2023-28252, CVE-2023-23397, CVE-2023-23376, CVE-2022-41082, CVE-2022-41080

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

ArgentinaAustraliaBrazilCanadaChinaCubaGermanyFranceUnited KingdomIndonesia

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersHospitalsEnterprises & HoldingManufacturingConstructionPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com