Nemty Ransomware
Nemty is a newly observed ransomware tool believed to be targeting European and CIS countries.
Summary
Nemty is a newly observed ransomware tool believed to be targeting European and CIS countries.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Nemty is delivered, although there are unconfirmed reports indicating it may be distributed via compromised Remote Desktop Services connections.
Once installed, Nemty will check the default language before sending user and system information to a command and control server. It will then attempt to encrypt all non-system files using an unknown algorithm.
Update 9 Sep 2019
Further details regarding Nemty's delivery methods have come to light. The latest variant (1.4) is delivered by the RIG exploit kit via spoofed versions of legitimate websites. Unlike previous versions, this variant will not target CIS countries.
Update 17 Sep 2019
The latest variant of Nemty, version 1.4, is now being distributed by the Radio exploit kit alongside RIG.
Update 17 Oct 2019
The latest Nemty version - 1.6 - has been observed in the wild being delivered by the RIG exploit kit. This variant uses the standard Windows cryptographic libraries in place of previous Nemty variant's custom AES implementation.
Update 06 Nov 2019
A new Trik campaign has been observed delivering Nemty 1.6 one exposed SMB ports using an updated list of default credentials
Remediation steps
| Type | Step |
|---|---|
|
If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
Update 17 Oct 2019 An open-source decryption tool has been released that is able to recover files encrypted by Nemty versions 1.4 to 1.6. Please note that NHS Digital do not test or verify such tools and organisations use them at their own risk. |
Last edited: 11 January 2022 1:29 pm