Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252).
Rust-based encryptor using Salsa20
Deletes shadow copies
Used Windows CLFS zero-day CVE-2023-28252
Uses Cobalt Strike and PowerShell