BreachCensus

nefilim

First seen May 5, 2020Active15 claimed victims

The claims below are reproduced as posted by nefilim on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
The MADSACK Media Group. Part 2.September 9, 2021ransomware_live
Tegut. Part 2.September 9, 2021ransomware_live
Saipa Press. Part 1.September 9, 2021ransomware_live
TPG Internet. Part 1.September 9, 2021ransomware_live
Tegut. Part 1.September 9, 2021ransomware_live
The MADSACK Media Group. Part 1.September 9, 2021ransomware_live
Seven Seas. Part 1.September 9, 2021ransomware_live
Elliott Group / Cascade Engineering / Unitex Textile Rental Services. Teaser.September 9, 2021ransomware_live
Grimmway Farms. Part 1.September 9, 2021ransomware_live
Atlanta Allergy & Asthma. Part 1.September 9, 2021ransomware_live
WhirlpoolDecember 1, 2020ransomware_live
DKA (refrigeration and air conditioning specialist, Dussmann Group subsidiary)July 27, 2020ransomware_live
Orange (mobile operator)July 4, 2020ransomware_live
Fisher and Paykel AppliancesJune 1, 2020ransomware_live
Toll GroupMay 5, 2020ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).