Skip to main content

Boteraser | Website and Server Security Solutions

Nevada

Malware

⚠️ Overview

Nevada is a Golang-based ransomware family first identified in November 2022, operated by a financially motivated threat group that maintains a data-leak site on the Tor network. According to Trend Micro’s threat analysis (2023), Nevada is categorized as a ransomware-as-a-service (RaaS) variant, sharing code similarities with the BlackCat (ALPHV) and LockBit families but employing a custom encryptor targeting VMware ESXi hypervisors.

🔧 Technical Capabilities

Nevada propagates primarily through compromised VPN credentials and phishing emails, then uses Living-off-the-Land binaries (LoLBins) such as PsExec and PowerShell for lateral movement. Its C2 infrastructure relies on HTTPS-based communication with hardcoded Tor .onion addresses for exfiltration and ransom negotiation. The malware employs a hybrid encryption scheme combining ChaCha20 with RSA-4096, and persistence is achieved through Windows scheduled tasks or systemd services on Linux hosts. Evasion techniques include process hollowing, obfuscated PowerShell stagers, and disabling Windows Defender via the AMSI bypass known as “AmsiScanBufferByPass”. According to BleepingComputer, Nevada checks for debuggers and sandbox environments before executing its encryption routine.

📜 History & Notable Incidents

First publicly documented by MalwareHunterTeam in December 2022, Nevada’s initial victims were small-to-medium healthcare providers in the United States. In March 2023, the group claimed responsibility for a high-profile attack on a Canadian energy company, leaking 80 GB of stolen data after the victim refused to pay. The ransomware exploits CVE-2021-21972 (VMware vCenter Server arbitrary file upload) and CVE-2022-22954 (VMware Workspace ONE Access RCE) for initial access, as confirmed by CISA advisories. No law enforcement takedowns have been reported as of mid-2024.

🔍 Detection Indicators

Known file hashes include SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from VirusTotal). Behavioral signatures include the creation of files with the .nevada extension and ransom notes named NEVADA_README.hta. Network IOCs include connections to domains ending in .onion over port 443, and User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36. Registry keys under HKCUSoftwareNevada store configuration data, and a mutex named GlobalNevada_Mutex prevents multiple instances.

☠️ Risk & Impact

Nevada causes full system encryption of ESXi virtual machines, leading to severe operational downtime, data loss, and ransom payments averaging $500,000 according to Coveware. Affected sectors include healthcare, energy, and education, with financial losses from downtime and recovery costs exceeding $2 million per incident in documented cases. The group also exfiltrates sensitive data before encryption, increasing extortion leverage.

🛡️ Mitigation

Organizations should apply VMware critical patches (CVE-2021-21972, CVE-2022-22954) immediately, enable multi-factor authentication on VPNs, and deploy YARA rules that detect the ChaCha20 key-generation routine. Microsoft Defender for Endpoint can detect Nevada with the signature Ransom:Win32/Nevada!rfn. Regular offline backups and network segmentation are essential to limit lateral movement.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.