Uptime Hamster: 10d 12h 41mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza nemty

nemty

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Nemty Revenge 2.0, Nefilim, Nemty Project, Nemty Doxware, Nephilim
Ver en IntelTracker → APTTrail →
Nemty emerged in August 2019 as a Ransomware-as-a-Service (RaaS) offering, notably featuring an exclusion mechanism for encrypting systems within specific Commonwealth of Independent States (CIS) countries like Russia, Belarus, Kazakhstan, Tajikistan, and Ukraine. Instead of encryption, it sends system data from these regions back to the operators, suggesting a potential Russian-speaking origin for the group. Initially, Nemty garnered attention due to some artifacts observed in its distribution methods that bore resemblance to Sodinokibi and GandCrab, though direct ties were not definitively established. In April 2020, the Nemty RaaS publicly announced its shutdown, transitioning to a more private and exclusive operational model. This shift followed the release of several decryptors for earlier versions of their ransomware and the emergence of Nefilim ransomware, which shares substantial code with Nemty, indicating a possible acquisition of Nemty's code base rather than a direct evolut

Aliases del actor

Nemty Revenge 2.0NefilimNemty ProjectNemty DoxwareNephilim

Actores similares

booba-projectactor · 7nefilimransomware · 2projectrelicransomware · 2ProjectSauronapt · 0RevengeHotelsapt · 0Project34 Ransomwareransomware · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownzjoxyw5mkacojk5ptn2iprkivg5clow72mjkyk5ttubzxprjjnwapkad.onionnemty
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: nemty
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArmeniaAustraliaAzerbaijanBelgiumBelarusChinaGermanyEgyptItalyKyrgyzstan

Sectores objetivo (SOCRadar)

Construction of BuildingsEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionOil & GasAircraft ManufacturingClothing StoresMining

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com