Nemty

Malware

⚠️ Overview

Nemty is a ransomware family first identified in August 2019 by security researchers at MalwareHunterTeam and initially analyzed by BleepingComputer. It operates as a file-encrypting ransomware that demands payment in Monero or Bitcoin, and is believed to be developed by a Russian-speaking threat actor known as "Jsworm" based on code similarities and shared infrastructure. Nemty falls under the ransomware category but has evolved to include data theft (double extortion) in later variants, aligning with the modern ransomware-as-a-service model.

🔧 Technical Capabilities

Nemty propagates primarily through exposed Remote Desktop Protocol (RDP) services, brute-force attacks, and phishing emails containing malicious attachments or links. It employs a complex encryption routine using a combination of RSA-2048 and ChaCha20 algorithms, appending the extension .nemty to encrypted files. The malware communicates with its command-and-control (C2) infrastructure via HTTP POST requests to hardcoded IP addresses, often using Tor for anonymization. Persistence is achieved by creating a scheduled task named "Nemty" and dropping a ransom note named "RESTORE_FILES.txt" in each affected directory. Evasion techniques include checking for sandbox environments by enumerating running processes and disabling Windows Defender via PowerShell commands. Nemty also terminates over 200 services and processes (e.g., SQL Server, backup software) before encryption to maximize damage, as documented by Trend Micro in their analysis.

📜 History & Notable Incidents

First appearing in August 2019, Nemty gained attention in September 2019 when it was used in attacks against Mexican businesses, including a major telecommunications firm (details published by ZDNet). In October 2019, a version of Nemty was observed being distributed through the RIG exploit kit, leveraging a malicious ad campaign (malvertising). No specific CVEs are uniquely associated with Nemty; instead it exploits weak RDP credentials and unpatched vulnerabilities in older software. Law enforcement has not publicly taken action against the group, but researchers at Cisco Talos tied Nemty to the "Jsworm" threat actor through shared IP addresses and code reuse.

🔍 Detection Indicators

Known SHA-256 hashes for Nemty samples include 5c8e8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f8a8f (example from VirusTotal submitted report). Behavioral indicators include creation of the mutex "NemtyMutex" to prevent multiple instances, and the ransom note "RESTORE_FILES.txt" containing the text "Your files are encrypted!". Network indicators involve HTTP POST requests to IP addresses in the 185.x.x.x range (e.g., 185.225.19.23) with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" (as observed by Malwarebytes). Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named "Nemty" are used for persistence.

☠️ Risk & Impact

Nemty causes irreversible file encryption, leading to potential data loss for victims who lack offline backups. The double-extortion variant exfiltrates sensitive data before encryption, threatening to leak it on public leak sites if the ransom is not paid. Affected sectors include small-to-medium businesses and healthcare organizations, with financial demands ranging from 0.05 to 2.0 Bitcoin per incident, according to reports from BleepingComputer.

🛡️ Mitigation

Defensive measures include enforcing strong RDP password policies, enabling multi-factor authentication, and restricting RDP access via VPN only. Organizations should maintain offline backups and implement endpoint detection rules (e.g., Sigma rules for PowerShell disabling Defender) as recommended by the MITRE ATT&CK framework (T1486 for data encryption). Regular patching of CVE-2019-0708 (BlueKeep) and other remote code execution vulnerabilities is advised, though Nemty primarily relies on stolen credentials rather than exploits.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.