Skip to content

Malware

Nefilim

aka Nephilim

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5.

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.


Family metadata imported from Malpedia (Fraunhofer FKIE).