Nokoyawa is a RaaS-based double-extortion ransomware group targeting South America.
Analyst brief
Nokoyawa is a double-extortion ransomware group that emerged in 2022, operating a RaaS model managed by 'farnetwork'. It primarily targets healthcare, financial services, government, and manufacturing sectors in South America. The group leverages a Windows CLFS zero-day (CVE-2023-28252) for privilege escalation, alongside custom encryptors and exfiltration tools characteristic of double-extortion TTPs. Defenders should prioritize patching CVE-2023-28252, enforce robust network segmentation, and monitor for anomalous C2 communications and unauthorized data transfers.
nokoyawa
crime
Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252).