惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Recent Announcements
Recent Announcements
V
Visual Studio Blog
博客园 - 叶小钗
H
Help Net Security
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
D
DataBreaches.Net
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
About on SuperTechFans
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence

RansomLook – Last entries

Panzer · RansomLook Unsafe · RansomLook Barracuda · RansomLook Cry0 · RansomLook Orion · RansomLook Dark Project · RansomLook Orova · RansomLook Gammax · RansomLook Booba Team · RansomLook Exfilsquad · RansomLook Global Secret Group · RansomLook Blackout · RansomLook Syndicate · RansomLook D1r · RansomLook Crpx0 · RansomLook Dataleak · RansomLook Arcus Media · RansomLook Doommageddon · RansomLook Redact · RansomLook Settra · RansomLook Wallstreet · RansomLook Cloak · RansomLook Deadlock · RansomLook 3am · RansomLook Direwolf · RansomLook Inc Ransom · RansomLook Qilin · RansomLook Bavacai · RansomLook Killsec3 · RansomLook Black X · RansomLook
Black Nevas · RansomLook
RansomLook · 2026-04-15 · via RansomLook – Last entries

35posts (all time)

0last 30 days

0last 7 days

67% avg uptime 30d

Parsing: enabled

View crypto

Description

BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct derivative of the Trigona ransomware family and continues the lineage's focus on extortion over public shaming. BlackNevas operators support a double-extortion model, encrypting files using AES-256 with RSA-4112-protected keys, and appending the .-encrypted or .ENCRYPTED file extension to affected files. Hybrid payloads are available for Windows, Linux, NAS, and VMware ESXi platforms.

While BlackNevas does not host its own data leak site, it reportedly collaborates with other ransomware groups for data publication — known partners include Kill Security, Hunters International, DragonForce, Blackout, Embargo Team, and Mad Liberator. The group has predominantly targeted large enterprises in sectors such as finance, telecommunications, manufacturing, healthcare, and legal. Initial access is commonly achieved via phishing or exploitation of vulnerabilities, with lateral movement facilitated through SMB enumeration and optional LAN-wide propagation.

External Analysis2
Mail4
Telegram1
Urls1
Activity (interactive) 35
Posts35