Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blacknevas

Also known as: Trial Recovery

Description

BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme. Known victims: 31

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

BlackNevas is a ransomware group first observed in April 2023, suspected to be derived from the Trigona family, targeting sectors like telecommunications and medical services primarily in亚太地区, the UK, Italy, and Lithuania. Known for double extortion using AES/RSA encryption, BlackNevas has successfully targeted over 31 organizations, highlighting their growing threat in the ransomware landscape.

Goals & Targeting

BlackNevas primarily seeks financial gain through ransomware activities. Their targeting strategy focuses on sectors with sensitive data, high recovery costs, and potential willingness to pay ransoms. Geographically, they concentrate on regions where organizations might have higher susceptibility or slower incident response, enhancing their campaign success rate.

Enhanced Description

BlackNevas emerged in April 2023 as a significant player in the ransomware ecosystem, evolving from the Trigona family. This group specializes in double extortion tactics, encrypting victims' data with a combination of AES and RSA encryption to increase pressure for payment. Targeting sectors such as telecommunications, manufacturing, medical, and legal services, BlackNevas has demonstrated a regional focus on Asia-Pacific countries, the UK, Italy, and Lithuania. Their operations include notable campaigns against entities like PROMOSFERA S.R.l., KINAS SOLICITORS, and Heng An Standard Life Insurance. The group's activities underscore advanced tactics aimed at maximizing financial gain through targeted extortion.

Key Capabilities

  • Double extortion tactics
  • Advanced ransomware implementation (AES/RSA encryption)
  • Targeted phishing campaigns
  • Network lateral movement techniques

MITRE ATT&CK Tactics

Data Destruction
Exfiltration or Transfer of Data
Impact System Availability

Software / Tooling

Trigona ransomware

Campaigns & Victims

BlackNevas has executed campaigns against various industries, with a focus on sectors offering high-value data. Their victims include prominent companies across Asia-Pacific and Europe. Notable campaigns involve targeting legal and healthcare firms, indicating strategic selection based on data sensitivity.

IOC Patterns

  • Ransomware payloads delivered via phishing emails

Recommended Actions

  • Monitor for known ransomware IOCs involving SHA-256 hashes
  • Enhance email filtering to detect phishing attempts
  • Implement network segmentation to limit lateral movement

Suggested Tags

Ransomware
Financial-Crime
Medical-Sector

Confidence Assessment

Confidence in BlackNevas' details is moderate. Data on their TTPs, linked MITRE techniques, and associated tools is limited, which hinders comprehensive analysis. Additional intelligence would improve understanding of their capabilities and modus operandi.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 20
SHA-256 Hash 20
f25f76a85ded0d4d285d9ae5482d8fe07dade3e241853d00b17642d7873733e8
75% TLP:CLEAR
a0630e2a81775e8334ea9f8cac73cebf1b9a70507ea3347c0c2eba82c80219a6
75% TLP:CLEAR
a331504acf589be5d11202232a7a93eeb4fe6b053beea231d9a0a661bcaf3fd6
75% TLP:CLEAR
b0dfaf509de38749c49afcb3cd34d27126044bb77cc16896b02ebced6f95db02
75% TLP:CLEAR
b2353fce403b079735a606294c4ffc20a71f1c6b16ec15e94f554beafcddd1ea
75% TLP:CLEAR
bad3c2f72ef2be522a554a9615dc93027416a3d4048f77519fca5104fabba1f9
75% TLP:CLEAR
bf4adad2eb1163369c133ae61c181a3f91ef8640a457e9c4e72d77a60fbfa7ab
75% TLP:CLEAR
c08a752138a6f0b332dfec981f20ec414ad367b7384389e0c59466b8e10655ec
75% TLP:CLEAR
c0fc61631a20c373ce17e939e09cfb4f5179c9e0788e80079b4ee8986afe89bd
75% TLP:CLEAR
d953bce4d87f5837ce318481e3a1b6617cf64af976043d3b4b4866475bb31972
75% TLP:CLEAR
def75a41435dc28430097a7e116b2d17526ce2b0172995618f2749b0d732f7ea
75% TLP:CLEAR
e7706a633f24679c7550a31b96088dda8f772c98f64daee7cfbf0dc17a4a8338
75% TLP:CLEAR
eb8cbc4a0eae33bfdc4ecb99d033c81224b005e55588ceb86346f2b2d3fd790f
75% TLP:CLEAR
95e744ddcc2e8f89f6c6e25503eff2eb5e70e98f6989bb4a4e93f17b09448e78
75% TLP:CLEAR
9d9c146910f294b3e2a755f76e8066cd2edfac057ff54f00f405e2f9e8b9e51a
75% TLP:CLEAR
2b9fe8a2629727470be1c928f7c9be7e2ea6cc22fb12f971902bf9cea8b16afb
75% TLP:CLEAR
360758c296310ba428d0d52c90e31c05fc43d5889282fa840283cf468f2378e8
75% TLP:CLEAR
3d09e930305cb3aa4ca54a39b0e3749f083d432f202606c8adac8455014b47fc
75% TLP:CLEAR
43f145fccec00f1e100ec3377eaf0ab60df3b9c5291b8011e05141cc04704be1
75% TLP:CLEAR
49fcbd606ff10d4661e222b8910ab7829d1668e3c97f1bab7eb51e8ec7d799a5
75% TLP:CLEAR

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

17

Campaigns

27

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Financial-Crime
Medical-Sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 24, 2023
Last Seen
Aug 1, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.