Ransomware Group intelligence
Nefilim
InactiveTrack Nefilim with 15 published victims and 1 known leak locations in a single intelligence view.
Overview
Nefilim is tracked by Breach House as a ransomware group with 15 published victims.
Australia is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | hxt254aygrsziejn.onion |
Top Activity Sectors (6)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Nefilim, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: nefilim executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: nefilim disables antivirus tools and security software to prevent detection and ensure ransomware execution proceeds unimpeded.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: nefilim deletes Volume Shadow Copies and backup files via system commands to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: nefilim brute-forces local accounts to obtain credentials for persistence and further network access.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1135 Network Share Discovery Discovery
What they do: nefilim scans network shares using SMB tools to identify victim files and expand foothold across the network.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: nefilim moves laterally through SMB/Windows Admin Shares to access additional systems within the victim environment.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: nefilim encrypts victim files using its ransomware payload, targeting documents and data directories for maximum disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: nefilim invokes system commands to inhibit recovery processes and lock down affected services post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
nefilim.txt
Two things have happened to your company. ========================================================================================================================== All of your files have been encrypted with military grade algorithms. The only way to retrieve your data is with our software. Restoration of your data requires a private key which only we possess. ========================================================================================================================== Information that we deemed valuable or sensitive was downloaded from your network to a secure location. We can provide proof that your files have been extracted. If you do not contact us we will start leaking the data periodically in parts. ========================================================================================================================== To confirm that our decryption software works email to us 2 files from random computers. You will receive further instructions after you send us the test files. We will make sure you retrieve your data swiftly and securely and that your data is not leaked when our demands are met. If we do not come to an agreement your data will be leaked on this website. TOR link: http://hxt254aygrsziejn.onion Contact us via email: [email protected] [email protected] [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (15)
Search, filter and paginate the victim timeline for Nefilim. Showing 1–15 of 15.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Atlanta Allergy & Asthma. Part 1. id1114 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grimmway Farms. Part 1. id1113 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Elliott Group / Cascade Engineering / Unitex Textile Rental Services. Teaser. id1112 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Seven Seas. Part 1. id1111 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The MADSACK Media Group. Part 1. id1110 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tegut. Part 1. id1109 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TPG Internet. Part 1. id1108 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Saipa Press. Part 1. id1107 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tegut. Part 2. id1106 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The MADSACK Media Group. Part 2. id1105 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Whirlpool id537 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DKA (refrigeration and air conditioning specialist, Dussmann Group subsidiary) id446 View details | Germany | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Orange (mobile operator) id438 View details | France | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Fisher and Paykel Appliances id392 View details | New Zealand | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Toll Group id370 View details | Australia | Services | — | |
|
No additional victim description available. |
|||||