Unveiling the Secrets: The Elusive Threat Actor “farnetwork” and their Reign in the Ransomware Landscape

In March 2023, Group-IB’s Threat Intelligence team made a significant revelation as they delved into the clandestine world of farnetwork, an elusive threat actor linked to five notorious ransomware strains. Their investigation uncovered a prominent player in the Ransomware-as-a-Service (RaaS) market, orchestrating complex operations and managing a private RaaS program based on the Nokoyawa ransomware strain.

Farnetwork: A Closer Look at the Prominent Player

Farnetwork, also known as farnetworkl, jingo, jsworm, razvrat, and piparkuka, has emerged as a prominent player in the RaaS market. Their notoriety stems from their involvement with five notorious ransomware strains, creating havoc in the cybersecurity domain.

Farnetwork managed a private RaaS program centered around the Nokoyawa ransomware strain. This revealed their technical prowess and organizational skills, demonstrating their ability to orchestrate complex cyber operations.

Unraveling Farnetwork’s History: Group-IB’s Investigation

The investigation was initiated when Group-IB researchers sought to infiltrate a private RaaS program that employed the Nokoyawa ransomware strain.

As the investigation progressed, a series of revelations shed light on Farnetwork’s extensive criminal career, which could be traced back to 2019. This exposed their deep involvement in various ransomware projects, showcasing their expertise in ransomware development and RaaS (Ransomware as a Service) management.

Farnetwork’s Role in Notorious Ransomware Projects

Farnetwork played a significant role in the development and management of various ransomware projects, including JSWORM, Karma, Nemty, and Nefilim. Their involvement demonstrated their proficiency in ransomware development and their effectiveness in executing successful attacks.

Through their involvement in multiple ransomware projects, FarNetwork showcased their expertise in developing sophisticated ransomware strains and effectively managing RaaS programs. This highlighted their technical prowess and operational sophistication.

Dissecting Farnetwork’s Modus Operandi

Further investigation revealed Farnetwork’s intricate RaaS affiliate program. Affiliates within this program were granted access to compromised corporate networks, eliminating the need for network compromise and streamlining the ransomware attacks.

Farnetwork’s revenue distribution model for successful attacks was discovered, with affiliates receiving 65% of the ransom, the botnet owner taking 20%, and the ransomware owner claiming 15%. This profit-sharing strategy formed the foundation of their criminal operation.

Farnetwork’s Retirement and Group-IB’s Ongoing Vigilance

Despite Farnetwork’s announcement of retirement and the subsequent cessation of their Nokoyawa Dedicated Leak Site (DLS) operations, Group-IB’s Threat Intelligence team remains steadfast in their monitoring efforts.

Given Farnetwork’s extensive criminal history and potential for resurgence or involvement in future cyber threats, Group-IB emphasizes the importance of sustained vigilance to safeguard against evolving cyber threats.

The Importance of Proactive Cybersecurity Measures

The revelations surrounding Farnetwork’s activities serve as a stark reminder of the ever-present threat posed by cybercriminals. It highlights the need for organizations, cybersecurity experts, and enthusiasts to prioritize proactive measures to enhance their resilience against emerging and sophisticated ransomware attacks.

Being proactive in the face of evolving threats is crucial, given farnetwork’s activities and the ongoing evolution of cyber threats. This can be achieved by implementing robust security measures, conducting regular vulnerability assessments, staying updated with the latest security practices, and fostering a culture of cybersecurity awareness.

The in-depth investigation by Group-IB’s Threat Intelligence team unraveled the enigmatic world of the farnetwork, exposing its influential role in the ransomware landscape. Its involvement in various ransomware projects and the management of a private RaaS program demonstrated its expertise and sophistication. As the cybersecurity landscape continues to evolve, it is imperative that organizations and individuals remain vigilant, proactive, and adaptable in their approach to securing digital environments from ever-advancing threats.

Explore more

How Will ERP, SCM, and CRM Integration Shape Retail in 2026?

Modern retail logic distinguishes the Enterprise Resource Planning system as the organization’s financial brain, while the Supply Chain Management system acts as its physical nervous system. This analogy underscores the intricate dependency that defines the current retail environment, where the margin for error has narrowed significantly under the weight of globalized commerce and hyper-connected consumers. Today, in 2026, the retail

UiPath Shares Rally 25% Driven by Agentic AI Momentum

Market observers are watching the $16.01 mark as a psychological and technical floor that must hold if the stock is to avoid a correction toward the lower analyst consensus. This specific price point emerged as a focal point during a rapid mid-August surge that saw the enterprise software provider reclaim significant ground after a period of relative stagnation. Over the

How Is Binance Pay Enabling Crypto Payments Across Bhutan?

Binance Pay has integrated with DK Bank’s domestic QR network, allowing cryptocurrency payments at more than 3,700 merchants across Bhutan. This landmark collaboration represents a pivotal shift for the Kingdom, traditionally known for its cautious approach to global financial trends but now emerging as a leader in digital asset adoption. By leveraging the existing infrastructure of the Druk Kumuen (DK)

Why Institutional Finance Is Shifting to Public Blockchains

The failure of early enterprise blockchain efforts in 2016 illustrates the limitations of private networks and the necessity of moving toward more robust, public infrastructures. For years, the financial sector attempted to harness distributed ledger technology through permissioned consortiums, believing that gated environments offered the only viable path to regulatory compliance and data privacy. However, these isolated systems effectively recreated

How Is DeFi Reshaping the Global Financial System?

Moving financial reconciliation to a shared and immutable ledger shifts the cost of trust from expensive human auditors to efficient and fully auditable smart contract code. This fundamental transition is no longer a peripheral experiment but a structural overhaul of how value is processed and secured across global markets. As legacy systems face increasing pressure from the speed and transparency