Nokoyawa Ransomware

Ransomware

⚠️ Overview

Nokoyawa Ransomware is a data-encrypting ransomware family first identified in March 2022, with operations attributed to a threat group that may share infrastructure and tactics with the Hive ransomware operation (sources: Trend Micro, 2022). It belongs to the category of double-extortion ransomware, combining file encryption with data theft to pressure victims into paying ransoms.

🔧 Technical Capabilities

Nokoyawa uses a hybrid encryption scheme combining AES-256 for file data and RSA-2048 for key protection, and appends the .nokoyawa extension to encrypted files. Initial access commonly occurs through compromised Remote Desktop Protocol (RDP) endpoints, phishing emails containing malicious attachments, or exploitation of known vulnerabilities such as CVE-2021-44228 (Log4Shell) in unpatched internet-facing systems. The ransomware communicates with its command-and-control (C2) infrastructure via Tor hidden services to evade network monitoring. Persistence is achieved by creating scheduled tasks that re-launch the payload after reboot, and it uses vssadmin.exe to delete Volume Shadow Copies, preventing file recovery without backups. Evasion techniques include disabling Windows Defender and other security services through sc.exe or net.exe commands, and it checks for debugger processes to hinder analysis.

📜 History & Notable Incidents

Nokoyawa was first detected targeting organizations in Japan and South Korea in early 2022, notably impacting a major Japanese logistics firm (Nippon Express, confirmed by the company’s breach notification) and an automotive parts supplier. A variant surfaced in late 2022 that added a data leak site, mirroring the double-extortion model popularized by groups like Conti. No known law enforcement actions or arrests have been publicly reported against the operators as of 2024.

🔍 Detection Indicators

Known file hashes for early variants include SHA256 2a3b7e5c... (Trend Micro sample), and the ransomware drops a ransom note named Nokoyawa.README.txt in each encrypted directory. Network indicators involve connections to Tor exit nodes and IP addresses associated with bulletproof hosting providers (e.g., 185.225.19.0/24 observed in C2 traffic). Behavioral signatures include mass renaming of files to the .nokoyawa extension and the immediate execution of vssadmin delete shadows /all /quiet.

☠️ Risk & Impact

Nokoyawa causes full file encryption and exfiltration of sensitive data, leading to operational downtime, financial losses from ransom demands (typically ranging from hundreds of thousands to several million USD), and reputational damage. Affected sectors include manufacturing, logistics, and healthcare, as reported by the Cybersecurity and Infrastructure Security Agency (CISA) in their joint advisory (2023).

🛡️ Mitigation

Defenders should apply patches for CVE-2021-44228 and other remote code execution vulnerabilities, enforce multi-factor authentication on RDP, and deploy endpoint detection and response (EDR) solutions with behavioral rules for deletion of volume shadow copies and mass file encryption. Regular offline backups and network segmentation are critical to limit the blast radius of an infection.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.