Ransomware Interviews

CyberSecurityIL

Back to list

BlackNevas

September 2026
Q:

Researchers found that BlackNevas shares an identical AES-256 configuration-decryption key and structure with Trigona. Are you a continuation of the original Trigona team, a fork built from its code, or did you acquire the source code from someone else? Could you elaborate on what changed after the Ukrainian Cyber Alliance destroyed Trigona's infrastructure in 2023?

A:

We purchased the source code and adapted it to our needs. It is possible that the 2023 takedown affected the seller's decision to sell, but we had no involvement in that incident and cannot confirm its impact. We are not a continuation of Trigona, nor did we fork their project - we simply acquired the code and moved on. We are not interested in Trigona's past or future.

Q:

BlackNevas has been described as a closed, centralized operation rather than a public RaaS group. Is that accurate? If so, who performs initial access, etc.? Do you use access brokers or insiders?

A:

Yes, that's accurate. BlackNevas is a closed, centralized operation - we don't advertise ourselves publicly or take part in open RaaS ecosystems. Our inner circle is limited to a few verified teams who understand the nature of the work and are ready to handle any task. That said, we frequently get approached by other groups offering their services or partnership opportunities. This actually connects to your next question: we've previously worked as affiliates on several RaaS platforms ourselves, and we've built strong relationships with many of those partners. Over time, we've also used multiple ransomware strains, depending on the target and the situation. In terms of initial access, we don't rely on open access brokers - instead we operate through our trusted network of vetted partners and internal methods, which keeps our attack chains controlled from start to finish.

Q:

In August 2026, several BlackNevas victim posts explicitly named the companies providing their IT services. Were those providers themselves compromised and used as entry points into multiple customers, did you exploit credentials or remote-management tools they had deployed, or were you naming them only to increase pressure on the victims? How many organizations can compromising a single IT provider give you access to?

A:

You're asking the right questions. But let's be clear right away: we don't publish our exact tactics or target lists for a specific operation - that would be stupid. Still, the general logic should be obvious to you, so I'll answer honestly within what isn't itself instruction. Were the providers compromised and used as a springboard? Sometimes yes. Sometimes no. When we name a company that provides IT services, that doesn't always mean we hacked their servers specifically. We name them because they're part of the chain. If a client uses that provider's services, and the provider didn't secure its access channels, that's an entry point for us. But if we simply name the provider hoping clients start breaking contracts with them, that also works. Pressure is a weapon. What do we actually use? You mentioned credentials and remote-management tools. Let's put it this way: any normal IT provider has administrative access to client systems - VPNs, RMM agents, support tools, backups, antivirus consoles. That's no secret. If the provider has poor access control, no 2FA, and passwords live in a shared wiki - eventually that will find a use. When we get into one contractor, everything depends on the architecture. We might gain access to their own network, we might steal a credential vault, we might remotely execute commands through their RMM console across all clients. But rushing to break everything at once is bad operational hygiene. We don't aim to burn everything in one night. We'd rather have a couple of loud, confirmed incidents than a hundred unverified ones. So you named providers only for pressure? That too. Your reader has probably noticed: if we publish files from one client and write "obtained through this contractor," that contractor's clients start panicking before we've even done anything. They're scared even if their own data wasn't touched. That's a psychological effect - it amplifies our coercive reach. By naming the provider, we put them in the role of the guilty party, and their clients in front of a false choice: "pay us or deal with your contractor." How many organizations does one provider yield? It varies. A small firm that handles bookkeeping and IT for small businesses typically has 5 to 30 clients. A medium-sized MSP - from 50 to 200. If the provider segmented access properly, we won't get all of them. If they use one shared domain with the same password everywhere - we get all of them. But even one large client with valuable data is worth more than twenty small ones. So we don't count "maximum possible." We count "worst damage with minimal noise." Bottom line: naming providers isn't just an attack on them - it's a way to make everyone else doubt their own contractors. Trust is the most fragile asset in IT. We just point at it.

Q:

Public trackers show approximately 35 to 41 BlackNevas victim listings. How many organizations have you actually compromised, and how many paid?

A:

Trackers see the storefront. We decide what to put on it and what to keep in the back room. To put it bluntly... imagine that inside the structure there are several autonomous teams working. Say, five. Each one averages one target closed per week. Not every week is perfect - there are pauses, glitches, targets that are too "noisy" and have to be abandoned. But the basic math is simple. Five teams. One target per week. That already adds up to more than two hundred fifty per year at full speed. We haven't worked a full year at that pace, and we don't publish anywhere near everything. So the figures you see on the trackers... that's not even half. It's closer to a quarter, and sometimes less. The payment rate is the only metric that really interests us. It's sufficient. If it dropped below a certain threshold, we'd already have changed our approach. For now... for now everything is within normal limits. I won't give you the exact numbers. Not out of modesty. There's just no point. All you need to understand is this: what enters the public sphere is not reporting. It's a pressure tool. The real volume of work stays inside.

Q:

BlackNevas listed LEARN, a Connecticut educational service organization. LEARN later disclosed that potentially affected information included Social Security numbers, diagnoses, disabilities, medical histories, prescriptions, etc. Do you consider children, schools, or special-education data off-limits? If not, what boundaries do you claim to have?

A:

We don't have any romantic notions about "off-limits zones." There's only a calculation of risk and return. Schools and educational organizations usually have weak defenses, outdated systems, and large volumes of personal data. From an operational standpoint, that makes them an attractive target. The fact that the data includes children doesn't automatically make the target untouchable. Our boundaries are different. We try to avoid targets where the consequences could trigger a disproportionate level of attention from law enforcement and politicians - hospitals in the middle of a crisis, critical infrastructure that could lead to immediate loss of life, and certain high-level government structures. Not out of humanism. Out of pragmatism. Children's data... is just another type of information. Valuable, sensitive, and effective at applying pressure during negotiations. We don't choose targets based on the age of the victims. We choose them based on accessibility and the potential price of the issue. If you're looking for a moral justification - there isn't one. We're not a charity and we're not knights. We make money. However, we do not release data from schools, universities and hospitals to the public.

Q:

In the Choithrams post, BlackNevas offered employee passports and claimed that an IT employee could be "forced to cooperate" because you possessed highly compromising information about them. Was this person already acting as an insider before the breach, someone you recruited afterward, or simply an employee you intended to blackmail?

A:

It doesn't really matter which of the three options was used. What matters is the outcome. In the Choithrams case, we had materials that put one of their IT specialists in a very awkward position - personal, financial, things most people would prefer to keep hidden. We made it clear that cooperation was the least painful option available to him. Whether he was already helpful before the encryption, whether we approached him after we'd already penetrated the system, or whether we simply used the materials as leverage to force him to cooperate... these are operational details. We're not discussing the exact sequence. I'll just say this: when you have something that can ruin a person's life outside of work, their willingness to protect the company tends to decline very quickly. This isn't recruitment in the classic sense. It's simply applied pressure. Effective, inexpensive, and usually effective. We don't rely on long-standing insiders as our primary method. But if an opportunity arises, we take it.

Q:

BlackNevas has referred to a partnership with Hunters International, which has publicly stated that it would not attack Israeli organizations. Does BlackNevas share that position and consider Israel off-limits? If so, why: ideology, personal views, law-enforcement risk, or something else?

A:

Partnerships are business arrangements, not marriage vows. Hunters International can set whatever internal rules they want for their own operations. That doesn't automatically become our policy. We don't consider any country off-limits on ideological or personal grounds. Including Israel. Decisions are made the same way we decide everything else - risk versus potential return. If a target in a particular country carries significantly higher law-enforcement attention, diplomatic noise, or operational complications, we weigh that. Sometimes the risk is acceptable. Sometimes it isn't. Geography itself is never the deciding factor. Capability of the target's defenses, value of the data, and likelihood of payment are. So no, we don't share a blanket "Israel is off-limits" position. If the numbers work and the risk is manageable, the location is irrelevant. Ideology is a luxury for people who don't have to answer for the results.

Q:

Threat actors like you constantly face better defenses, law-enforcement pressure, and faster incident response. What's your long-term strategy for staying operational and evolving faster than the defenders?

A:

Defenders get better. That's inevitable. Tools improve, response times shrink, awareness rises. Anyone who expects the old methods to keep working forever is already finished. Our approach is simple: treat this like any other competitive business that operates under constant pressure. We don't rely on a single technique, a single entry method, or a single infrastructure for long. Everything is modular. When something starts to burn - a particular access vector, a hosting provider, a payment route, even a public brand - we discard it and replace it. Speed of replacement matters more than perfection. Long-term survival comes from three things: Constant testing of new approaches before the old ones fully die. Keeping the core small and the periphery disposable. Never becoming emotionally attached to any tool, affiliate, or even the current name. Law enforcement pressure and faster incident response are just part of the operating environment, like weather. You don't fight the weather. You build so that rain doesn't stop the work.

Q:

Do you use AI tools in any part of your operations?

A:

Of course. Anyone who doesn't is already falling behind. AI is just another tool - like better scanners, better translators, or better ways to sort large amounts of data. We use it where it saves time or improves results: analyzing collected information, generating variations of text, helping with language barriers, spotting patterns that a human might miss under time pressure. Nothing mystical about it. The same way defenders are using AI to detect us faster, we use it to move faster than their detections. It's an arms race of efficiency. The side that refuses to pick up the new tools loses.

Q:

What is the weirdest request you have ever received from a victim during negotiations?

A:

There have been a few. One that still stands out: a mid-sized company, after three days of negotiation, suddenly asked if we could provide a formal letter on our "official letterhead" confirming that the attack had been a sophisticated nation-state operation and not the result of their own poor security. They wanted to show it to their board and insurance company so the IT director wouldn't get fired. They were willing to pay the full amount... but only if we helped them rewrite the internal story. We declined the letter. They paid anyway. People under pressure come up with the strangest ways to protect their own positions. Money is rarely the only thing on the table.

Q:

What advice would you give companies that want to avoid becoming your next target?

A:

Most of the advice is boring, which is why so few follow it. If a company actually wants to reduce the chance of becoming a target, they should stop treating security like a compliance checkbox. Patch the obvious things quickly. Remove unnecessary remote access. Enforce real multi-factor authentication everywhere it matters - not the kind that can be bypassed with a tired employee and a phone notification. Segment the network so that one compromised account doesn't open the entire kingdom. Keep offline, tested backups that actually work when everything else is on fire. And above all: assume that someone is already looking at you. The organizations that last longest are the ones that make the cost of the operation higher than the expected return. We don't waste time on hard targets when easier ones are available. Everything else - fancy tools, expensive reports, colorful dashboards - is secondary. Most breaches still start with something simple that was left open for convenience. Close the simple things, and you drop off the list of attractive opportunities. That's it. No secret knowledge required. Just discipline.

Q:

Is there anything else you'd like to say or share with my 40,000 followers?

A:

Not really. Most of the people who will read this already know how the game works, or they soon will. The ones who still think this is about ideology, politics, or some grand statement are wasting their time. It's a business. High risk, high margin, constant adaptation. If your followers are on the defending side - improve the basics, or don't. The market will sort it out either way. If they're simply curious... now you've had a look behind the curtain. It's less dramatic and more methodical than the stories usually suggest.

All rights reserved to the Telegram channel 讞讚砖讜转 住讬讬讘专. Content displayed is an exact transcription of the original interviews without modification.

base44
Edit with Base44