Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies

Posted on September 15, 2025September 15, 2025 By CWS

The BlackNevas ransomware group has emerged as a major risk since November 2024, repeatedly launching devastating assaults in opposition to companies and important infrastructure organizations throughout Asia, North America, and Europe.

This subtle malware operation combines file encryption with knowledge theft techniques, threatening to leak stolen info if ransom calls for are usually not met inside seven days.

The ransomware demonstrates a very aggressive concentrating on technique, with roughly 50% of its assaults centered on the Asia-Pacific area.

International locations together with Japan, Thailand, and South Korea have skilled substantial impacts, whereas European targets span Western Europe and the Baltic Sea area, together with the UK, Italy, and Lithuania. In North America, the group has particularly focused organizations in Connecticut.

Menace actor’s Telegram deal with throughout the ransom observe (Supply – ASEC)

ASEC researchers recognized that BlackNevas operates independently with out following the normal Ransomware-as-a-Service mannequin.

The risk actors preserve their very own knowledge leak web site and declare partnerships with affiliated teams to stress victims into compliance.

The malware appends the distinctive “.-encrypted” extension to compromised recordsdata, making the encryption instantly obvious to victims.

Not like many ransomware variants that incorporate anti-debugging or sandbox evasion methods, BlackNevas takes a unique method by supporting a number of command-line arguments that modify its habits.

The malware consists of parameters reminiscent of “/quick” for encrypting just one p.c of file content material, “/full” for full file encryption, and “/stealth” for altering extensions and creating ransom notes through the encryption course of.

Superior Encryption Implementation and File Focusing on Technique

The ransomware employs a complicated dual-encryption method combining AES symmetric keys with RSA public key cryptography.

Through the encryption course of, BlackNevas generates a singular AES key for every file, encrypts the content material, then secures the AES key utilizing an embedded RSA public key earlier than appending it to the tip of the encrypted file.

The malware demonstrates selective concentrating on by excluding essential system recordsdata to take care of system stability.

Take a look at surroundings after encryption is full and the desktop is modified (Supply – ASEC)

Protected extensions embrace sys, dll, exe, log, bmp, vmem, vswp, vmxf, vmsd, scoreboard, nvram, and vmss recordsdata, together with particular recordsdata like “NTUSER.DAT” and its personal ransom observe “how_to_decrypt.txt”.

Curiously, BlackNevas creates two distinct filename patterns throughout encryption: customary recordsdata obtain randomized names with the “-encrypted” extension, whereas particular doc varieties together with doc, docx, hwp, jpg, pdf, png, rtf, and txt recordsdata are prefixed with “trial-recovery” as an indication of decryption capabilities.

Ransom observe (Supply – ASEC)

The encryption verification course of entails checking 8-byte values at file endings to find out encryption standing and file sort classification.

This system eliminates native decryption prospects, because the RSA personal key stays solely with the attackers, making file restoration unattainable with out paying the ransom or possessing superior cryptographic capabilities.

Increase your SOC and assist your workforce shield your small business with free top-notch risk intelligence: Request TI Lookup Premium Trial.

Cyber Security News Tags:Affected, BlackNevas, Companies, Data, Encrypts, Files, Ransomware, Sensitive, Steals

Post navigation

Previous Post: Mustang Panda With SnakeDisk USB Worm and Toneshell Backdoor Seeking to Penetrate Air-Gap Systems
Next Post: Terra Security Raises $30 Million for AI Penetration Testing Platform

Related Posts

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data Cyber Security News
NoName057(16)’s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months Cyber Security News
Global Jewellery Brand Pandora Suffers Hacked Cyber Security News
Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 Cyber Security News
Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT Cyber Security News
New FireWood Malware Attacking Linux Systems to Execute Commands and Exfiltrate Sensitive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Japan Issues OT Security Guidance for Semiconductor Factories
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • Historic Great Firewall Breach – 500GB+ Censorship Data Exposed
  • WhatsApp Introduces Passkey Encryption for Enhanced Chat Message Backup Security
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Japan Issues OT Security Guidance for Semiconductor Factories
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • Historic Great Firewall Breach – 500GB+ Censorship Data Exposed
  • WhatsApp Introduces Passkey Encryption for Enhanced Chat Message Backup Security
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News