Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis
Essential information
- Published
- 12/09/2025 07:41
- Modified
- 12/09/2025 08:23
- Tags
- 2025-09-12 aes asia-pacific blacknevas data leak encryption global threats ransomware rsa
- Related entities
- 1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 11 others
Description
The BlackNevas ransomware group, first appearing in November 2024, has been targeting various industries and critical infrastructure globally, with a focus on the Asia-Pacific region. The group uses AES and RSA encryption, adding the '.-encrypted' extension to affected files. BlackNevas operates independently, threatening to leak data on their own site and through partners. The ransomware supports multiple arguments, excludes certain system paths and file types from encryption, and uses a unique method to check for previous infection. It also creates ransom notes in all accessible folders, demanding negotiation within seven days to prevent data leaks.