Nemty

Malware updated a month ago (2024-11-29T14:51:17.029Z)
Download STIX
Preview STIX
Nemty is a type of malware, specifically ransomware, that infiltrates systems to exploit and damage them. It was developed by a cybercriminal group known as farnetwork, which has been active since 2019. Farnetwork has been involved in several ransomware projects, including JSWORM, Nefilim, Karma, and Nemty. These malicious programs have the ability to disrupt operations, steal personal information, or hold data hostage for ransom. The group has been linked to various Ransomware-as-a-Service (RaaS) schemes between 2019 and 2021. In 2022, farnetwork launched their own RaaS program based on Nokoyawa ransomware, an evolution of the Nemty and Karma ransomware families. This move was expected due to farnetwork's prior experience deploying both Nemty and Karma strains. Throughout its cybercriminal career, farnetwork has used multiple handles, such as farnetworkl, jingo, jsworm, razvrat, piparkuka, and farnetworkit, and has helped develop ransomware and manage the RaaS programs before launching their own. During its tenure, farnetwork managed to secure significant ransom payments from its victims. In 2019, it was reported that the RaaS project they managed — believed to be Nemty — received ransom payments averaging $1 million per victim initially, which later fell to about $600,000. For successful attacks carried out using Nokoyawa’s ransomware, affiliates received 65% of the ransom amount, with 20% going to the botnet owner and 15% to the developer.
Description last updated: 2024-05-04T16:44:34.359Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Nefilim is a possible alias for Nemty. Nefilim is a malware, specifically a ransomware, that has been responsible for significant cyber threats globally. It infiltrates systems through suspicious downloads, emails, or websites and can steal personal information, disrupt operations, or hold data hostage for ransom. Between 2019 and 2021,
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
RaaS
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Jsworm Malware is associated with Nemty. JSWorm is a type of malware, specifically ransomware, that was active from 2019 to 2021. This malicious software was developed and operated by a threat actor known as 'farnetwork', who has used various aliases including farnetworkl, jingo, jsworm, razvrat, piparkuka, and farnetworkit. Farnetwork gaiUnspecified
3
The Farnetwork Malware is associated with Nemty. Farnetwork, a notorious malware operator identified by cybersecurity researchers from Group-IB, has been active in the cybercrime scene since 2019. Known for deploying five different strains of ransomware, including its proprietary strain Nokoyawa, Farnetwork has collaborated with other cybercriminaUnspecified
2
Source Document References
Information about the Nemty Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more