Back to Groups
nefilim
INACTIVEAccording to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
0
Total Victims
First Seen
Unknown
Last Active
Unknown
Known Sites
1