logo

BlackNevas Ransomware Encrypts Files, Exfiltrates Corporate Data

ID: 4860f882-fec0-55ea-8e16-fd34753e8071

STIX ID: report--4860f882-fec0-55ea-8e16-fd34753e8071

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2025-09-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

BlackNevas is a sophisticated dual‑extortion ransomware group operating across Asia‑Pacific (50% of operations), Western Europe, and select U.S. targets; it encrypts files using per‑file AES keys wrapped with RSA, appends a distinctive ".-encrypted" extension (with special "trial-recovery" naming for demonstration files), supports multiple command-line modes (/fast, /full, /allow_system, /debug, /stealth, /shdwn), performs runtime path analysis to avoid system-critical directories, and threatens stolen data via a proprietary data leak site and partner networks—requiring organizations to focus on prevention, EDR/behavioral detection, and anti‑exfiltration controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.