Unveiling the Secrets: The Elusive Threat Actor “farnetwork” and their Reign in the Ransomware Landscape

In March 2023, Group-IB’s Threat Intelligence team made a significant revelation as they delved into the clandestine world of farnetwork, an elusive threat actor linked to five notorious ransomware strains. Their investigation uncovered a prominent player in the Ransomware-as-a-Service (RaaS) market, orchestrating complex operations and managing a private RaaS program based on the Nokoyawa ransomware strain.

Farnetwork: A Closer Look at the Prominent Player

Farnetwork, also known as farnetworkl, jingo, jsworm, razvrat, and piparkuka, has emerged as a prominent player in the RaaS market. Their notoriety stems from their involvement with five notorious ransomware strains, creating havoc in the cybersecurity domain.

Farnetwork managed a private RaaS program centered around the Nokoyawa ransomware strain. This revealed their technical prowess and organizational skills, demonstrating their ability to orchestrate complex cyber operations.

Unraveling Farnetwork’s History: Group-IB’s Investigation

The investigation was initiated when Group-IB researchers sought to infiltrate a private RaaS program that employed the Nokoyawa ransomware strain.

As the investigation progressed, a series of revelations shed light on Farnetwork’s extensive criminal career, which could be traced back to 2019. This exposed their deep involvement in various ransomware projects, showcasing their expertise in ransomware development and RaaS (Ransomware as a Service) management.

Farnetwork’s Role in Notorious Ransomware Projects

Farnetwork played a significant role in the development and management of various ransomware projects, including JSWORM, Karma, Nemty, and Nefilim. Their involvement demonstrated their proficiency in ransomware development and their effectiveness in executing successful attacks.

Through their involvement in multiple ransomware projects, FarNetwork showcased their expertise in developing sophisticated ransomware strains and effectively managing RaaS programs. This highlighted their technical prowess and operational sophistication.

Dissecting Farnetwork’s Modus Operandi

Further investigation revealed Farnetwork’s intricate RaaS affiliate program. Affiliates within this program were granted access to compromised corporate networks, eliminating the need for network compromise and streamlining the ransomware attacks.

Farnetwork’s revenue distribution model for successful attacks was discovered, with affiliates receiving 65% of the ransom, the botnet owner taking 20%, and the ransomware owner claiming 15%. This profit-sharing strategy formed the foundation of their criminal operation.

Farnetwork’s Retirement and Group-IB’s Ongoing Vigilance

Despite Farnetwork’s announcement of retirement and the subsequent cessation of their Nokoyawa Dedicated Leak Site (DLS) operations, Group-IB’s Threat Intelligence team remains steadfast in their monitoring efforts.

Given Farnetwork’s extensive criminal history and potential for resurgence or involvement in future cyber threats, Group-IB emphasizes the importance of sustained vigilance to safeguard against evolving cyber threats.

The Importance of Proactive Cybersecurity Measures

The revelations surrounding Farnetwork’s activities serve as a stark reminder of the ever-present threat posed by cybercriminals. It highlights the need for organizations, cybersecurity experts, and enthusiasts to prioritize proactive measures to enhance their resilience against emerging and sophisticated ransomware attacks.

Being proactive in the face of evolving threats is crucial, given farnetwork’s activities and the ongoing evolution of cyber threats. This can be achieved by implementing robust security measures, conducting regular vulnerability assessments, staying updated with the latest security practices, and fostering a culture of cybersecurity awareness.

The in-depth investigation by Group-IB’s Threat Intelligence team unraveled the enigmatic world of the farnetwork, exposing its influential role in the ransomware landscape. Its involvement in various ransomware projects and the management of a private RaaS program demonstrated its expertise and sophistication. As the cybersecurity landscape continues to evolve, it is imperative that organizations and individuals remain vigilant, proactive, and adaptable in their approach to securing digital environments from ever-advancing threats.

Explore more

How to Make Money With Lead Generation in 2026

The digital landscape has transformed into a high-stakes battlefield where businesses are no longer searching for simple contact information but are instead hunting for verified, high-intent connections amidst a sea of automated noise. If a professional spent any time online a few years ago, it was impossible to escape the constant claims from influencers that lead generation represented the ultimate

Financial AI Evolution Requires New Network Infrastructure

The silent cost of a single dropped data packet in a multi-day high-frequency AI training cluster can burn through thousands of dollars in a heartbeat, yet most banks are still running on pipes built for the era of static spreadsheets. As the industry moves through 2026, the transition of artificial intelligence from experimental side-projects to the central nervous system of

Is AI Integration Outpacing Governance in Global Finance?

The financial landscape is shifting beneath the surface as sophisticated algorithms now execute complex trades and predict market fluctuations with a speed that human analysts simply cannot match. This rapid evolution has pushed 77% of financial organizations to integrate artificial intelligence into their core operations. However, a jarring discrepancy exists, as only 14% of these firms are operating under a

How Are Cobots and AI Transforming Industrial Automation?

The rhythmic, synchronized movement of robotic arms no longer occurs behind thick plexiglass or steel mesh, as the walls once defining the factory floor have begun to disappear in favor of seamless interaction. This transition represents a $16.7 billion pivot toward collaborative intelligence, where machines are no longer isolated assets but active partners. As the industry moves into a more

BNPL Growth Challenges US Merchants With Fraud and Disputes

The meteoric rise of installment-based spending has fundamentally altered the American retail landscape, yet the very convenience that drives consumer conversion is now triggering a complex crisis of fraud and operational instability for merchants. Retailers today find themselves in a precarious position where providing the most popular payment options often means opening the door to sophisticated financial threats that bypass