← All ransomware groups

Ransomware group profile · #104 by claimed victims

Blacknevas ransomwarealso Trial Recovery

BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.

Active First seen Aug 2025
46Victims claimed on leak sites
1Victims in the last 30 days
15Victims in the last 90 days
19Countries hit
0Leak-site URLs tracked
8 Sep 2026Latest claim recorded

Victimology

Who Blacknevas claims to have breached, from 46 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 5OctNov 2025: 0Dec 2025: 0Jan 2026: 1JanFeb 2026: 0Mar 2026: 0Apr 2026: 8AprMay 2026: 0Jun 2026: 2Jul 2026: 4JulAug 2026: 8Sep 2026: 1

Top sectors

Manufacturing10
Retail & E-Commerce9
Professional Services8
Technology7
Hospitality3
Energy & Utilities2
Healthcare2
Other1

Top countries

United States11
India5
Turkiye4
United Kingdom3
Spain3
Italy3
Thailand2
Japan2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Mefa Group www.mefagroup.com.tr / MEFA Endüstri www.mefaendustri.com / and (Efac mefagroup.com.tr Manufacturing TR 8 Sep 2026
ASCOM S.p.A. ascom-italy.it serviced by an IT company Emilcom S.r.l. emilcom.it Manufacturing IT 14 Aug 2026
Portable Intelligence Inc www.portable-intelligence.com serviced by an IT compan portable-intelligence.com Technology US 13 Aug 2026
Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company westbrooksystems.com Agriculture and Food Production US 12 Aug 2026
Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company C enteroptyx.com Healthcare US 12 Aug 2026
Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced therg.ca Professional Services CA 12 Aug 2026
COMPUTER COUNTRY AND NETWORKS Technology 12 Aug 2026
OTEGROUP otegroup.com Other OM 7 Aug 2026
Arkın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm B arkingroup.com Hospitality TR 4 Aug 2026
Speed Group Transportation 28 Jul 2026
Zuni Shopping Center, Inc. halonaplaza.com Retail & E-Commerce US 22 Jul 2026
L'azurde Retail & E-Commerce SA 14 Jul 2026

All 46 Blacknevas victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Blacknevas is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Blacknevas ransomware still active?
Blacknevas is tracked as active. The most recent leak-site claim VULONE recorded is dated 8 September 2026. 1 victims were claimed in the last 30 days.
How many victims has Blacknevas claimed?
VULONE has recorded 46 leak-site victim claims attributed to Blacknevas since August 2025, across 19 countries and 12 sectors.
Which industries does Blacknevas target?
The sectors most often named on the Blacknevas leak site are Manufacturing, Retail & E-Commerce, Professional Services.
Which countries are most affected by Blacknevas?
Most Blacknevas victims recorded by VULONE are located in United States, India, Turkiye.
Where does VULONE get Blacknevas victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].