Nemty

Nemty is ransomware with an unusually complex encryption algorithm. This malware encrypts user files and demands money so that they can be unlocked again. It may be connected to other famous ransomware, but we don’t know for sure.

Type
Ransomware
Origin
ex-USSR territory
First seen
1 August, 2019
Last seen
30 March, 2020
Also known as
NEMTY PROJECT
Global rank
32
Week rank
20
Month rank
22
IOCs
54

Nemty, also known as NEMTY PROJECT is a ransomware-type of malware. A virus that puts encryption on all files that are stored on infected machines and only allows to restore them if victims pay a certain ransom amount.

Nemty has surfaced not so long ago. It was first observed in the wild in August 2019. Due to some similarities in the code and behavior, researchers think than Nemty might be related to GandCrab and Sodinokibi, though direct correlation hasn’t been proved. In any case, it is safe to assume that this is a very advanced malware.

Additionally, the malware’s code apparently includes an affiliate ID which may indicate that Nemty is available as a Ransomware as a Service. If this information is correct Nemty has the potential to become a very widespread malware due to it’s easy availability.

General description of Nemty

Nemty ransomware is being actively upgraded by its creators. In fact, several versions of the virus have already been released and nothing suggests that this development should stop anytime soon.

Among other upgrades, threat actors employed a very strong encryption algorithm. It is actually so strong that no malware before Nemty has used anything similar. The RSA-8192 used here is 8192-bit encryption which is considered to be an overkill for use in malware. Even though this encryption protocol makes data decryption more difficult it also presents its own complications. For example, it causes longer encryption and key generation times and only encrypts 1024 bytes at a time.

Despite this, researchers have been able to create decryptors that work with versions 1.4, 1.5 and 1.6 of the malware. This means that victims that have been attacked by the version of the malware mentioned above can restore their information without having to pay the ransom the attackers.

Without the decryptors, victims would have to pay a ransom of about $1000 equivalent in Bitcoin to the attackers. The ransom can be paid through a payment portal that is hosted using the TOR network. And if not paid on time, the amount is doubled to a $2000 equivalent.

We don’t know for sure who the people behind Nemty are. The malware has code that checks if the victim is from one of the following countries: Russia, Belarus, Kazakhstan, Tajikistan, or Ukraine.

However, victims from the countries mentioned above can still get attacked by the ransomware. This is strange since usually, viruses that check for the origins of victims terminate execution to avoid getting attention from local law enforcement structures.

In the case of Nemty, users from all over the world are in danger of being infected.

However, there are other interesting oddities in the code that point to a ex-USSR origin of the virus. The code contains a link to a similar picture that was linked in GandCrab’s code. Except, this time it contains on an overlay of the Russian president’s portrait. There are other weird things to be found in the code of this malware. For example, if you dig deep enough you will find a direct message to cybersecurity professionals telling them to, well, “mind their own business” in a less polite form.

More evidence suggesting the x-USSR origin of the malware creators is that the payment page is in the Russian language. Maybe the creators are in fact Russian or they are trying to plant a false lead and mislead researchers.

Malware analysis of Nemty Ransomware

A video recorded in the ANY.RUN malware hunting service allows us to take a look at the execution of this malware in action.

nemty's ransom note

Figure 1: Nemty's ransom note

text report of the Nemty ransomware analysis

Figure 2: Shows a customizable text report generated by the ANY.RUN malware analysis service which allows diving deeper into the details of the Nemty execution process.

Nemty execution process

The execution process of the Nemty ransomware is relatively typical for this type of malware. After the executable file makes its way into an infected system and runs, the main malicious activity begins. Like many other ransomware families, Nemty deletes shadow copy files. It also stops and kills processes from the hardcoded list. The malware creates a text file with a ransom note in every folder with encrypted files.

The interesting thing is that Nemty, as well as Sodinokibi, creates a registry key in which it stores values such as a public key and a file extension for encrypted files.

Nemty Distribution

Initially, Nemty was using RIG and Radio EK exploit kits for distribution purposes. In addition to that, malware authors employed spam email campaigns to distribute the virus primarily in Korea and China. These two countries are where the bulk of all Nemty infections is happening.

However, with the newer versions of the malware coming out, threat actors started using new distribution methods. Possibly they were trying to expand the reach of the malware and gain the ability to infect more victims.

One of such methods is a fake PayPal website that promises to save money with an unusually high cashback. The website is designed to look identical to the genuine PayPal and prompts users to download a file called “cashback.exe”. Although unsuspecting victims might think that they are downloading a PayPal app, in reality, they are installing and executing the Nemty ransomware.

In addition, later versions of the malware are delivered using the Trik botnet. Apparently, the authors of Nemty have partnered up with people behind Trik to increase their range.

How to detect Nemty using ANY.RUN?

To determine whether the sample under review is Nemty or not, you can take a look at the changes that it made in the registry. To do so, open "Advanced details of process" of the malicious process and look at the "Registry changes" tab in the "Events" section. If a process has created values with the names "cfg", "pbkey" or "fid" into the key HKEY_CURRENT_USER\Software\NEMTY, you can be sure that the given sample is Nemty.

changes in registry made by nemty ransomware

Figure 3: Changes in registry made by Nemty ransomware

Conclusion

The constant evolution of distribution methods, as well as regular updates, prove that this malware is at a stage of active development. First seen in 2019, Nemty is a young threat that already shows signs of sophisticated malware.

Coupled with the potential use of the Ransomware as a Service business model that makes this malware available to many threat actors around the globe, these factors demand that this threat is not taken lightly.

One of the primary dangers of this Ransomware lies in the delivery techniques chosen by the attackers. While mail spam helps to reach millions of potential victims easily, heavy use of exploit kits allows attackers to control every step of the infection.

Thus, it is especially important that security researchers can evaluate this ransomware and continue developing countermeasures and encryptors. One tool that can help in this pursuit is the ANY.RUN malware hunting service that will allow studying samples of Nemty in a controlled and safe environment.

IOCs

IP addresses
184.73.185.65
23.21.83.121
54.243.186.202
54.204.26.223
174.129.223.190
204.236.231.159
54.225.66.103
54.204.24.179
23.21.59.179
54.225.71.235
184.73.165.106
104.26.4.15
50.16.245.226
54.243.147.226
50.19.115.217
104.26.5.15
54.225.139.71
54.225.159.35
54.235.203.7
23.21.50.37
Hashes
57e25a37d8279fe563415d636b1983d447b5521ec6c024e18fd4d578840d2e20
518394d105b9f9f1c375efe6038468e595bfd4e848940b9af6c6f563f00bbe26
32b3df537b2569ca4848b6245a01332ddd6aa1cfd90d6e3ef50f10e611a8e6f9
31ee05823a66851cf6965f32d02e767206785d0bf0c9fa65e7dcf1ffed32c18e
177736d35ad6a35d1ef041b69dfdd3ea919098d4f1ff14f9827c3f325e948d85
0aed298cdbbb21d34f0e21dcfccfb7373d03c85c892e95e3570f86a219348478
0fa90452f44a63c56d29857132ff742e1f2a3d4d53b9512420df8322cd694368
d9796426092ae05f5c6115905aa6fa677ed746713eb1d65b865c70dbe24b7f33
8eed4849865afb225030a11c5c71ac1804cb27e052528017d64dcf643082d674
f15d8981dcd217c2154de5c8f28c63962878353d8b848f9c109398aa564e7c49
c295b52dcc29deace11ba0bdc48505eaae23cf5d5656cea97cf9884216ab0cb1
451c0ec2815d72fdbf3629649427f28a1bd850d0edc0ef7c052c96ad580caa3d
12da8dee83df90880d7d9cb4b0a7b608950bb57e9bc59c8b96f68c364350447c
bff4af2eb55e3b40c05b93c06748015ad6af243c84fc016a0383e90fa424070a
613c390d6b3b792d6bf0765e97719ac4278741abcebdd03d9fe394c8a46a841c
b893f726f30f3a63bc899383f724ab7b8e8e4d674db40efa5972d23cb8ed1a8a
4799d051f0e40b15ec67593ea838df901613018d26b612d6d2447431323d4a01
4cf87dd16d57582719a8fe6a144360f3dfa5d21196711dc140ce1a738ab9816e
cc496cec38bbc72bae3cb64416baca38b3706443c4f360bd4ba8300d64b210d2
8ee3fcde25866ac62159f0ff3ac1482f3d25de140ec434adbbd5d44396832781
Domains
go.techtarget.com
majul.com
isns.net
qxq.ddns.net
api.db-ip.com
api-netn.db-ip.com
www.beautypaths.eu
cdn.db-ip.com
api-osisoft.db-ip.com
api-mg2.db-ip.com
krupskaya.com
m-onetrading-jp.com
thuocnam.tk
i.kissmetrics.com
e4280.g.akamaiedge.net
qaloqum.com
kmccs-201209-cert-2056600847.us-east-1.elb.amazonaws.com
nagano-19599.herokussl.com

HAVE A LOOK AT

Adwind screenshot
Adwind
adwind trojan
Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat and JSocket is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
Ave Maria screenshot
Ave Maria
avemaria stealer trojan rat
Ave Maria malware is a Remote Access Trojan that is also called WARZONE RAT. Hackers use it to control PCs of their victims remotely and steal information from infected PCs. For example, they can remotely activate the camera to take pictures of a victim and send them to a control server
Read More
Azorult screenshot
Azorult
azorult trojan rat
AZORult can steal banking information including passwords and credit card details as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat.
Read More
Crimson RAT screenshot
Crimson RAT
crimson rat trojan
Crimson is a Remote Access Trojan — a malware that is used to take remote control of infected systems and steal data. This particular RAT is known to be used by a Pakistani founded cybergang that targets Indian military objects to steal sensitive information.
Read More
Danabot screenshot
Danabot
danabot trojan stealer
Danabot is an advanced banking Trojan malware that was designed to steal financial information from victims. Out of the Trojans in the wild this is one of the most advanced thanks to the modular design and a complex delivery method.
Read More