216.73.216.6

Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis

· Published 12/09/2025 07:41 · Modified 12/09/2025 08:23

Export JSON

Essential information

Published
12/09/2025 07:41
Modified
12/09/2025 08:23
Tags
2025-09-12 aes asia-pacific blacknevas data leak encryption global threats ransomware rsa
Related entities
1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 11 others

Description

The group, first appearing in November 2024, has been targeting various industries and critical infrastructure globally, with a focus on the region. The group uses and , adding the '.-encrypted' extension to affected files. operates independently, threatening to leak data on their own site and through partners. The supports multiple arguments, excludes certain system paths and file types from , and uses a unique method to check for previous infection. It also creates ransom notes in all accessible folders, demanding negotiation within seven days to prevent data leaks.

External references