Netskope Threat Labs

Nemesis

ATP Sandbox Adv. HeuristicsAV

Nemesis is a detection name for trojan malware that provides remote access and data exfiltration capabilities on infected systems. Detections under this name indicate an implant that maintained operator channels and collected files, credentials, and other data for upload. Analysts should treat the detection as part of a broader intrusion and investigate the chain that delivered the payload.

First seen
February 2022
Last seen
October 2026
Alert Name
Binary.Malware.Nemesis
Binary.Trojan.Nemesis
Gen:Variant.Adware.Nemesis.1
Gen:Variant.Adware.Nemesis.110
Gen:Variant.Adware.Nemesis.13455
Gen:Variant.Adware.Nemesis.14688
Gen:Variant.Adware.Nemesis.201
Gen:Variant.Adware.Nemesis.398
Gen:Variant.Adware.Nemesis.417
Gen:Variant.Adware.Nemesis.535