Black Nevas is a ransomware threat group that emerged in 2024 and has publicly claimed multiple victims across several sectors and countries. Reported victims include organizations in the United States, Canada, and Saudi Arabia, with affected sectors including information technology, health care, industrial and logistics-related businesses, and consumer-facing enterprises. Publicly attributed incidents indicate both ransomware deployment and associated data-breach activity, including theft of confidential corporate information for extortion pressure. Observed victimology includes software and warehouse-management providers, ophthalmology-related businesses, customs brokerage and logistics firms, greenhouse systems manufacturers, retail and hospitality operators, and jewelry manufacturing and retail organizations. In at least one reported case, the group claimed exfiltration of a large volume of technical, customer, and production data, indicating a pattern consistent with data-theft-enabled ransomware operations. Black Nevas has been identified among the newer ransomware groups active in the 2024–2026 period and has also been listed among groups participating in the broader rise of ransomware activity affecting Korean companies and their overseas subsidiaries. High-confidence reporting supports characterization of Black Nevas as a financially motivated cybercriminal actor focused on ransomware and extortion rather than espionage. Publicly available information in this dataset does not establish a reliable country of origin, organizational structure, or confirmed sub-groups beyond the alias form black_nevas.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Portable Intelligence Inc.
Conducting a ransomware attack resulting in a data breach against Westbrook Greenhouse Systems.
Conducting a ransomware attack resulting in a data breach against Enteroptyx Ophthalmology Products in the United States.
Conducting a ransomware attack resulting in a data breach against Jack Rutherford Customs Brokers Ltd / The Rutherford Group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.