BlackNevas is a ransomware strain, identified as a descendant of Trigona, that encrypts victim data using a combination of AES and RSA. It appends the .-encrypted extension to affected files and drops a ransom note named how_to_decrypt.txt. The note states that files were encrypted and confidential data was stolen, threatens deletion of decryption keys after seven days, and instructs victims to contact the operators via email or Telegram. Reported contact details include asherjon@myself.com, reserve emails compsupp@techie.com, paymeuk@consultant.com, and Serina5Murrock@email.com, and the Telegram handle @BlackNevas. The malware was observed in early August 2025 and was identified by ID Ransomware on August 26, 2025. It is described as targeting English-speaking users but capable of global distribution. Reported distribution vectors include exposed or insecure RDP, phishing emails, malicious attachments, exploit-based delivery, deceptive downloads, fake updates, botnets, malicious advertising, web injects, and trojanized or repacked installers. BlackNevas targets common user and business data types including Microsoft Office and OpenOffice documents, PDFs, text files, databases, photos, music, videos, disk images, and archives. Relevant file locations mentioned include the Desktop, user folders, and %TEMP%, and the executable may use a random filename in the format <random>.exe. Reported indicators include MD5 f34e1ef922fd065e25b55faa021aefae, SHA-1 78ba10ca8cad98cea075b6725093a06dfe08d43a, SHA-256 cb27ae30a0654bc1cf51d476eeef18eea502c406c1c025142b8d2f7c9cafd8f4, imphash d1ff72de48440e9c1c5a2199d7bda4c2, and related intermediate variant SHA-256 hashes 3d09e930305cb3aa4ca54a39b0e3749f083d432f202606c8adac8455014b47fc, 501821a19ccf59830789849beff94238736adb4b213870a511890c5c8efab2a6, and 40a40eaf3e2a634d5d9ae4131ffb21c9210d4991ba56b3536bb10284a6e94717. Multiple Tor onion addresses were also reported as associated infrastructure. A separate reporting source cited BlackNevas among mid-volume emerging ransomware groups, accounting for 5 incidents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Emerging ransomware brand referenced as part of the long-tail of operators impacting industrial organizations.
Ransomware that encrypts user data using AES+RSA, appends the .-encrypted extension, drops a ransom note named how_to_decrypt.txt, and claims data theft for extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.