◇ SIGN IN
← all actors
ransomware

BlackNevas

activemedium confidence
Ransomware
Black NevasTrial Recovery
Attribution
Financially motivated (unattributed; Trigona-family variant)
Origin
Unknown
First seen
2024
Last active
2025
Motivation
Financially motivated (ransomware / double extortion)
Confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Consumer goods, professional services, manufacturing, IT, financial services

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Consumer goods, professional services, manufacturing sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

BlackNevas is a double-extortion ransomware operation first detected in November 2024, assessed as a Trigona-family variant, that encrypts Windows, Linux, NAS and VMware ESXi systems and relies on other groups' infrastructure for data publication rather than hosting its own leak site.

History

BlackNevas (also referenced as 'Trial Recovery') was first detected in November 2024 and quickly spread across Asia, Europe and North America, hitting healthcare, finance, manufacturing, legal and telecom targets. Technically it is assessed as a variant of the Trigona ransomware family and supports Windows, Linux, NAS devices and VMware ESXi, combining AES-RSA encryption with data theft; encrypted files carry a distinctive '.-encrypted' extension and ransom notes direct victims to negotiate via email or Telegram.

Unlike most double-extortion crews, BlackNevas reportedly does not operate its own dedicated leak site; instead it is said to collaborate with other groups for data publication, with reported partners including Kill Security, Hunters International, DragonForce, Blackout, Embargo and Mad Liberator. Its extortion approach emphasizes negotiation and profit over public naming-and-shaming, with reported multi-million-dollar demands and short (around 7-day) payment deadlines for enterprise targets.

BlackNevas appears to operate independently rather than as a broad RaaS. Its MENA-relevant claims include Saudi Arabia and the UAE. Because it leans on partner channels for publication, victim claims may be harder to attribute and should be treated as unverified unless confirmed by a reputable source or the affected organization.

Notable campaigns

2024
BlackNevas emergence
Detected November 2024 as a Trigona-family double-extortion variant hitting enterprises across three continents (claims).

Claimed victims · 39 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
OTEGROUPOmanOther
Speed GroupTransportation
Zuni Shopping Center, Inc.USRetail & E-Commerce
L'azurdeSaudi ArabiaRetail & E-Commerce
Arkın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm BeachTürkiyeHospitality
Arkin GroupTürkiyeProfessional Services
Abans GroupLKRetail & E-Commerce
Abans FinservINRetail & E-Commerce
Bohmler Einrichtungshaus GmbHDERetail & E-Commerce
Carrera Casting Corp.USManufacturing
Heng An Standard Life InsuranceHKFinancial Services
E-CON Packaging Private LimitedINManufacturing