The BlackNevas ransomware group has emerged as a significant threat since November 2024, continuously launching devastating attacks against businesses and critical infrastructure in Asia, North America, and Europe .

This sophisticated malware operation combines file encryption with data theft, threatening to leak stolen information if ransom demands are not met within seven days.
The ransomware demonstrates a particularly aggressive targeting strategy, with approximately 50% of attacks focused on the Asia-Pacific. Countries such as Japan, Thailand, and South Korea have been significantly impacted, while European targets extend to Western Europe and the Baltic Sea region, including the United Kingdom, Italy, and Lithuania. In North America, the group has targeted organizations in Connecticut.
See also: New SEO Poisoning Attack Targets Windows Users
ASEC researchers have identified that the BlackNevas ransomware operates independently, not following the traditional Ransomware-as-a-Service model . The threat actors maintain their own data leak website and claim to work with affiliated groups to pressure victims into compliance.
The malware appends the distinctive “.-encrypted” extension to compromised files, making the encryption immediately apparent to victims. Unlike many ransomware variants that incorporate anti-debugging or sandbox-evasion techniques, BlackNevas takes a different approach by supporting multiple command-line arguments that modify its behavior.
Malicious software includes parameters such as “/fast” for encrypting only 1% of the file contents, “/full” for full file encryption, and “/stealth” for changing extensions and creating ransom notes during the encryption process.

BlackNevas ransomware: Advanced encryption
The ransomware uses an advanced approach dual-encryption combining AES symmetric keys with RSA public key cryptography. During the encryption process, BlackNevas generates a unique AES key for each file, encrypts the content, and then secures the AES key using an embedded RSA public key, before appending it to the end of the encrypted file.
See also: DarkCloud Stealer targets financial institutions
The malware exhibits selective targeting by excluding critical system files to maintain system stability. Protected extensions include sys, dll, exe, log, bmp, vmem, vswp, vmxf, vmsd, scoreboard, nvram, and vmss files, as well as specific files such as “NTUSER.DAT” and its own ransom note “how_to_decrypt.txt”.
Interestingly, BlackNevas ransomware creates two different file name patterns during encryption: standard files receive random names with the “-encrypted” extension, while specific document types, including doc, docx, hwp, jpg, pdf, png, rtf, and txt, receive the “trial-recovery” prefix as a demonstration of decryption capabilities.
The encryption verification process involves checking 8-byte values at the end of files to determine encryption status and file type classification. This methodology eliminates local decryption capabilities , as the private RSA key remains exclusively with the attackers, making file recovery impossible without paying a ransom or possessing advanced cryptographic capabilities.
See also: New Yurei Ransomware encrypts files with ChaCha20

Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
