Nokoyawa

THREAT ACTOR PROFILE

Nokoyawa

Nokoyawa

Nokoyawa

Nokoyawa is a ransomware operation that emerged in 2022, deployed at the end of hands-on-keyboard intrusions that often begin with the IcedID loader. Its intrusions follow the familiar eCrime pattern of maldoc or OneNote phishing, Cobalt Strike for lateral movement, and data exfiltration before encryption, placing it alongside other IcedID-fed ransomware families.

Not attributed

Ransomware

First seen

2022

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Nokoyawa and its IcedID lineage

Nokoyawa is tracked under its own name in our records. It maps to one entry among the ransomware operations we profile, and its IcedID-to-ransomware pattern overlaps with crews like Akira.

-

-

-

GROUP PROFILE

Hands-on-keyboard ransomware from IcedID access

Nokoyawa is a financially motivated ransomware operation. It sits at the end of a well-worn intrusion chain, where an initial loader infection is escalated by operators into full network compromise and encryption.

Our record ties it to ransomware intrusions that begin with IcedID. The DFIR Report documented cases where phishing with Microsoft OneNote or Excel maldocs delivered IcedID, which led to Nokoyawa ransomware after hands-on-keyboard activity.

The group's tradecraft uses Cobalt Strike and AnyDesk for lateral movement and reconnaissance, with FileZilla for exfiltration before the ransomware is deployed across file and backup servers.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

ATTACK LIFECYCLE

IcedID phishing into Nokoyawa ransomware

The stages below come from Nokoyawa-related activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

IcedID, Cobalt Strike and commodity tools

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through phishing, not CVE exploitation

Nokoyawa intrusions in our records begin with maldoc and OneNote phishing that delivers IcedID rather than with exploitation of a specific software vulnerability, and our records list no exploited CVEs for the operation. Coverage of Nokoyawa is thin in our current data. Detection should focus on the IcedID delivery chain, Cobalt Strike and AnyDesk use, and FileZilla exfiltration before encryption.

Nokoyawa

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Nokoyawa

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Nokoyawa

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Nokoyawa

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

OneNote and IcedID into Nokoyawa

Reporting tracks the intrusion chains ending in Nokoyawa.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Nokoyawa

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Nokoyawa

IOC set, full IP, host and hash history.