blacknevas
Known ransomware group ACTIVE Currently active
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
1
Total Claims
1
Critical
—
Records Claimed
1
Industries Hit
Active span: Sep 16, 2026 – Sep 16, 2026 · 1 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: Sep 2026 (1)Sep 2026
LessMore
Sep 2026Top Targeted Industries
Financial Services 1
Tradecraft & Infrastructure
0
Documented tools
0 / 0
MITRE tactics / techniques
1
Known leak sites