惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
雷峰网
雷峰网
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
B
Blog RSS Feed
H
Help Net Security
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
L
LangChain Blog
Vercel News
Vercel News

RansomLook – Last entries

Panzer · RansomLook Unsafe · RansomLook Barracuda · RansomLook Cry0 · RansomLook Orion · RansomLook Dark Project · RansomLook Orova · RansomLook Gammax · RansomLook Booba Team · RansomLook Exfilsquad · RansomLook Global Secret Group · RansomLook Blackout · RansomLook Syndicate · RansomLook D1r · RansomLook Crpx0 · RansomLook Dataleak · RansomLook Arcus Media · RansomLook Doommageddon · RansomLook Redact · RansomLook Settra · RansomLook Wallstreet · RansomLook Cloak · RansomLook Deadlock · RansomLook 3am · RansomLook Direwolf · RansomLook Inc Ransom · RansomLook Qilin · RansomLook Bavacai · RansomLook Killsec3 · RansomLook Black X · RansomLook
Black Nevas · RansomLook
RansomLook · 2026-04-15 · via RansomLook – Last entries

35posts (all time)

0last 30 days

0last 7 days

67% avg uptime 30d

Parsing: enabled

View crypto

Description

BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct derivative of the Trigona ransomware family and continues the lineage's focus on extortion over public shaming. BlackNevas operators support a double-extortion model, encrypting files using AES-256 with RSA-4112-protected keys, and appending the .-encrypted or .ENCRYPTED file extension to affected files. Hybrid payloads are available for Windows, Linux, NAS, and VMware ESXi platforms.

While BlackNevas does not host its own data leak site, it reportedly collaborates with other ransomware groups for data publication — known partners include Kill Security, Hunters International, DragonForce, Blackout, Embargo Team, and Mad Liberator. The group has predominantly targeted large enterprises in sectors such as finance, telecommunications, manufacturing, healthcare, and legal. Initial access is commonly achieved via phishing or exploitation of vulnerabilities, with lateral movement facilitated through SMB enumeration and optional LAN-wide propagation.

External Analysis2
Mail4
Telegram1
Urls1
Activity (interactive) 35
Posts35