216.73.217.22

Nefilim Ransomware

· Published 24/02/2026 17:00 · Modified 24/02/2026 20:54

Export JSON

Essential information

Published
24/02/2026 17:00
Modified
24/02/2026 20:54
Tags
2026-02-24 CVE-2019-11634 CVE-2019-19781 aes-128 citrix credential-theft data exfiltration encryption lateral movement nefilim nemty netwalker ransomware rdp
Related entities
14 observables, 1 intrusion sets (apt), 13 techniques (mitre), 2 others

Description

emerged in March 2020, evolving from 's code. It targets vulnerabilities in gateway devices and uses exposed Remote Desktop Protocol for initial access. The malware exfiltrates sensitive data before and threatens to publish it if ransom isn't paid. uses tools like PsExec, Mimikatz, and LaZagne for and credential theft. It employs and drops a ransom note named '-DECRYPT.txt'. The has attacked high-profile targets like Toll Group. Mitigation strategies include strong passwords, disabling , regular backups, software updates, and monitoring for and .

External references