logo

Ransomware manager: Investigation into farnetwork, a threat actor linked to five strains of ransomware

ID: 5943ecd7-1c7d-5587-9db6-75c484479b9d

STIX ID: report--5943ecd7-1c7d-5587-9db6-75c484479b9d

Feed Name: Group-IB Blog

Threat Score
80/100

Date Published: 2023-11-08

Date Updated: 2026-04-27

...
...

Group-IB investigates and profiles a prolific cybercriminal operator alias 'farnetwork' (and related nicknames) who from 2019–2023 participated in and managed multiple ransomware-as-a-service programs (JSWORM, Nemty, Nefilim, Karma) and later ran a private Nokoyawa RaaS; the report documents their botnet-for-access model, affiliate recruitment and testing, revenue-sharing (65% affiliate / 20% botnet owner / 15% ransomware owner), use of stealer-sourced credentials (RedLine), dedicated leak sites exposing dozens of victims, and provides defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.