Back to Threat Groups

nefilim

INACTIVE

ransomware group

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.

Victims
15
records
First Discovered
May 5, 2020
victim
Last Discovered
Sep 9, 2021
victim
Inactive Since
1,847
days
Countries
4
hit
Avg Discount
—
no settlements

Group Activity

Last 12 months
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026
Jul
2026
Aug
2026
Sep
2026
Oct
2026