BlackNevas Ransomware Strikes Two More Organizations as the Threat Expands Its Reach + Video

Listen to this Post

Featured Image

A New Warning From the Dark Web

The ransomware landscape has become increasingly unforgiving, and the latest activity surrounding the BlackNevas operation shows why. On August 12, 2026, threat intelligence monitoring identified two organizations added to the group’s victim list, highlighting the continuing pressure that ransomware operators are placing on businesses that depend heavily on digital infrastructure.

The newly listed organizations are Jack Rutherford Customs Brokers Ltd / The Rutherford Group, associated with therg.ca, and Enteroptyx Ophthalmology Products, associated with enteroptyx.com. According to the ThreatMon Threat Intelligence Team, both organizations appeared in BlackNevas-related ransomware activity on August 12.

The development is significant because BlackNevas is not a newly emerged ransomware family. Security researchers have been tracking the operation since late 2024, and technical investigations have linked its malware lineage to the Trigona ransomware family. AhnLab reported that BlackNevas has targeted organizations across Asia, North America, and Europe, while other threat intelligence research has documented attacks involving Windows, Linux, VMware ESXi, and other environments.

Two Organizations Added to the Victim List

ThreatMon reported that Jack Rutherford Customs Brokers Ltd / The Rutherford Group was added to BlackNevas’s victim list at approximately 19:21 UTC+3 on August 12, 2026.

The organization is connected with the website therg.ca and is described in the monitoring entry as being serviced by an IT provider. That detail is particularly important because third-party IT relationships can create additional security dependencies. A compromise of an external provider, remote-management account, or shared administrative environment can potentially expose more than one organization.

A second entry followed almost immediately. Enteroptyx Ophthalmology Products, associated with enteroptyx.com and also described as being serviced by an IT company, was listed at approximately 19:22 UTC+3.

The close timing of the two entries does not by itself prove that the organizations were compromised through the same pathway. However, the appearance of multiple victims within roughly the same monitoring window illustrates how ransomware operations can maintain sustained targeting activity across different businesses.

BlackNevas Has a Documented History

BlackNevas first emerged in 2024 and has since developed a reputation for combining file encryption with data theft. AhnLab’s analysis described the group as an ongoing ransomware operation attacking businesses and critical infrastructure organizations in several regions. The researchers also linked its technical characteristics to Trigona.

Halcyon currently describes BlackNevas as a closed ransomware group with confirmed code lineage to Trigona. Its research indicates that the operation targets multiple platforms, including Windows, Linux, VMware ESXi, and ARM environments.

That cross-platform capability matters because modern companies rarely operate a single type of infrastructure. A business may have Windows workstations, Linux servers, virtualized workloads, cloud-connected systems, backup infrastructure, and remote administration platforms operating simultaneously.

The Real Danger Is Bigger Than Encryption

Traditional ransomware was primarily associated with encrypted files and ransom demands. BlackNevas represents a more dangerous model in which encryption can become only one component of a broader intrusion.

Security investigations have documented BlackNevas activity involving credential theft, network discovery, lateral movement, remote-management tools, data exfiltration, and destructive actions. One documented case involving a Hong Kong lifestyle company found that attackers remained inside the environment for nearly a week before encryption occurred. During that period, they harvested credentials, moved through the network, staged data, and deleted backup resources.

This changes the question organizations need to ask.

The question is no longer simply, “Can we stop ransomware from encrypting our files?”

The more important question is, “Can we detect an intruder before the final stage of the attack begins?”

BlackNevas Uses a Double-Extortion Strategy

BlackNevas has been associated with a double-extortion model. In this approach, attackers steal sensitive information before encrypting systems.

The victim therefore faces two separate pressures.

The first is operational disruption caused by encrypted systems.

The second is the threat of sensitive information being exposed, sold, or published.

AhnLab documented that BlackNevas steals sensitive information and threatens disclosure as part of its ransomware operation.

This model is particularly dangerous for companies holding customer records, commercial contracts, financial documents, employee information, intellectual property, or confidential communications.

Why Customs and Logistics Companies Can Be Attractive Targets

A customs brokerage organization sits at an important point in the commercial supply chain.

Such companies can process documentation involving shipments, importers, exporters, carriers, customs declarations, invoices, contact information, and other business records.

An attacker does not necessarily need to compromise a massive multinational corporation to generate leverage. A smaller organization may still possess information belonging to numerous customers and business partners.

That makes the potential data-access footprint much larger than the size of the targeted company might suggest.

Why IT Providers Increase the Security Stakes

Both newly reported entries contain references to organizations being serviced by IT companies.

That detail deserves attention.

Managed service providers and external IT companies can improve security by centralizing expertise, monitoring infrastructure, and maintaining systems. But they can also become high-value targets because their administrators may have privileged access to multiple customer environments.

A compromised remote-management account can potentially provide attackers with an efficient route into systems that would otherwise be difficult to reach.

This does not mean that either organization was compromised through its IT provider. The available report does not establish that connection.

It does mean that organizations relying on external IT services should treat provider access as part of their own attack surface.

BlackNevas and Legitimate Remote Administration Tools

One of the more concerning characteristics associated with BlackNevas is its documented abuse of legitimate remote-management software.

Threat intelligence reporting has identified tools including MeshAgent, AnyDesk, Atera, ScreenConnect, TeamViewer, and other remote-access technologies in BlackNevas intrusion activity.

This creates a difficult defensive problem.

Security teams cannot simply block every remote-management tool because many organizations legitimately depend on them.

Instead, defenders need to determine whether the tool is being used by the right account, from the right location, at the right time, against the right systems, and for the right purpose.

Credential Theft Can Become the Turning Point

Ransomware operators often do not need sophisticated zero-day exploits when stolen or weak credentials provide a simpler route.

BlackNevas investigations have documented credential-access techniques including credential dumping and domain-level credential theft.

Once privileged credentials are obtained, attackers may be able to move laterally without immediately triggering conventional malware alerts.

This is why identity security is now inseparable from ransomware defense.

A company can have modern endpoint protection and still suffer a devastating attack if an administrator account is compromised and sufficiently trusted by the environment.

VMware ESXi Environments Deserve Special Attention

Virtualization infrastructure is another important part of the BlackNevas threat picture.

Threat intelligence reporting has associated the group with attacks against VMware ESXi environments and documented exploitation of the ESXi Admins privilege-escalation issue, CVE-2024-37085.

Virtualization hosts are extremely valuable targets because one successful intrusion can affect multiple virtual machines simultaneously.

Instead of encrypting one workstation at a time, an attacker who reaches virtualization infrastructure may be positioned to disrupt servers supporting databases, applications, authentication, file storage, and business operations.

Data Theft Changes Incident Response

If attackers steal information before encryption, restoring systems from backups does not completely solve the incident.

The infrastructure may come back online, but the stolen information can remain outside the organization’s control.

That creates a second incident-response track involving legal review, privacy obligations, customer communication, threat monitoring, evidence preservation, and potentially regulatory notification.

For that reason, ransomware response plans must address both system recovery and data exposure.

The Importance of Immutable Backups

Backups remain one of the strongest defenses against ransomware, but the word “backup” alone is not enough.

BlackNevas-related investigations have documented attackers deleting or damaging backup resources before encryption. In the Hong Kong case studied by Blackpanda, the attackers removed the backup application and deleted backup data before encrypting systems.

Organizations therefore need backups that attackers cannot easily modify or delete.

Offline copies, immutable storage, separated credentials, restricted administrative access, and regular restoration testing can make the difference between a controlled recovery and a prolonged crisis.

A Ransomware Attack Often Begins Quietly

The most dangerous phase of a ransomware incident may happen before anyone sees a ransom note.

Attackers can spend days searching for credentials, identifying servers, mapping shares, discovering backups, and determining which systems contain valuable information.

By the time encryption starts, the attackers may already understand the environment.

That is why behavioral detection is so important.

A sudden administrative login from an unusual location, followed by remote-management deployment, network scanning, credential dumping, and abnormal file transfers should be treated as a potentially connected sequence rather than unrelated events.

The August 12 Listings Matter Beyond Two Companies

The appearance of Jack Rutherford Customs Brokers Ltd / The Rutherford Group and Enteroptyx Ophthalmology Products is important not simply because two names appeared on a ransomware monitoring feed.

It demonstrates that BlackNevas remains active in 2026.

Threat intelligence reporting has continued to track the group throughout the year, including incidents involving organizations in manufacturing, insurance, healthcare, and other sectors. Halcyon lists BlackNevas activity across multiple geographic regions and industries.

The lesson for defenders is straightforward.

A ransomware group does not need to dominate headlines every day to remain dangerous.

Persistent activity, repeated intrusion techniques, and the ability to exploit ordinary business infrastructure can be enough.

What Undercode Say:

BlackNevas Is an Operational Threat

BlackNevas should be viewed as an active operational threat rather than simply another ransomware strain.

Its importance comes from the combination of access, persistence, credential theft, data exfiltration, and encryption.

The group demonstrates how modern ransomware has evolved into a full intrusion operation.

Encryption is increasingly the final stage rather than the beginning of the attack.

The IT Supply Chain Is Part of the Attack Surface

The references to external IT providers in the two August 12 listings deserve particular attention.

Businesses often focus security controls on their own employees and devices.

That is no longer sufficient.

Managed service providers, remote-support companies, software vendors, cloud platforms, and outsourced administrators can all introduce additional privileged access pathways.

Every external administrator should therefore be treated as a potential high-value identity.

Identity Is Becoming the New Perimeter

Passwords remain one of the easiest ways for attackers to enter organizations.

MFA can dramatically reduce the value of stolen passwords, but only when implemented correctly and across privileged accounts.

Security teams should pay particular attention to administrator accounts, VPN access, remote-management platforms, cloud consoles, and service accounts.

Remote Tools Need Behavioral Monitoring

Blocking AnyDesk or similar software is not always practical.

Many companies use legitimate remote-management applications every day.

The better strategy is to monitor unusual behavior.

A remote tool suddenly installed on a server should receive more scrutiny than the same tool operating from a known administrator workstation.

A new remote-management service combined with credential dumping or network scanning should be considered especially suspicious.

Network Segmentation Can Limit the Blast Radius

A flat corporate network gives ransomware operators too much freedom.

If one workstation is compromised, attackers should not automatically be able to reach every server, backup system, hypervisor, and administrative workstation.

Segmentation creates barriers.

Those barriers slow lateral movement and provide defenders with additional opportunities to detect the intrusion.

Backups Must Be Protected From Administrators Too

An attacker who steals domain administrator credentials may eventually attempt to access backup systems.

That is why backup infrastructure should use separate authentication, separate administrative identities, and restrictive network policies.

The strongest backup is one the ransomware operator cannot reach.

Exfiltration Detection Is Essential

Organizations often invest heavily in detecting encryption but less in detecting data theft.

That balance needs to change.

Large transfers to unfamiliar cloud storage destinations, unexpected archive creation, abnormal outbound connections, and unusual use of synchronization tools can provide valuable warning signs.

Detecting the theft before encryption may provide the organization with its most important response window.

Logging Should Survive an Attack

Attackers frequently attempt to remove evidence.

Centralized logging helps preserve telemetry outside the compromised environment.

Security teams should consider sending authentication, endpoint, firewall, VPN, identity, and administrative events to infrastructure that cannot easily be modified by a compromised domain administrator.

Incident Response Needs a Ransomware-Specific Playbook

Generic incident-response plans may not be enough.

A ransomware playbook should identify who isolates systems, who contacts legal counsel, who manages communications, who protects evidence, who evaluates backups, and who coordinates restoration.

Every minute matters when dozens or hundreds of systems are at risk.

Recovery Testing Is More Important Than Backup Advertising

An organization may proudly report that it has backups.

The real question is whether those backups can be restored under pressure.

Recovery testing should measure how quickly critical applications can return to service.

The objective is not simply to possess copies of data.

The objective is to restore the business.

BlackNevas Shows Why ESXi Security Matters

Virtual infrastructure deserves the same security attention as endpoints.

Administrators should restrict access to ESXi management interfaces, monitor privileged group changes, patch known vulnerabilities, and protect hypervisor credentials.

A compromised virtualization layer can transform a single intrusion into a business-wide outage.

Threat Intelligence Should Feed Detection

Threat intelligence becomes valuable when it changes defensive behavior.

Knowing that BlackNevas has used particular remote-management tools, credential-access methods, and network-discovery techniques can help security teams build targeted detection rules.

Threat intelligence should therefore be connected to SIEM, EDR, XDR, firewall, identity, and network monitoring systems.

Small Businesses Are Not Automatically Low-Value Targets

Ransomware operators are economically motivated.

A smaller organization may still possess valuable customer information, sensitive documents, privileged relationships, or access to larger partners.

The question is not simply how much revenue a company generates.

The question is what the attackers can obtain through it.

Third-Party Access Requires Continuous Review

Organizations should maintain an inventory of external accounts and services with privileged access.

Unused accounts should be removed.

Temporary access should expire.

MFA should be enforced.

Administrative sessions should be logged.

Remote access should be restricted by network and identity policies whenever possible.

The First Objective Should Be Early Detection

Stopping every intrusion is unrealistic.

Detecting an intrusion before ransomware deployment is much more achievable.

Security teams should prioritize signals that reveal attackers moving through the environment.

Credential dumping, unusual remote administration, network scanning, suspicious service installation, privilege escalation, and abnormal data movement are all valuable warning signs.

BlackNevas Is a Reminder of the New Ransomware Model

The modern ransomware attack is not simply malware running on a computer.

It is an operation.

The attacker researches the environment.

The attacker steals credentials.

The attacker establishes persistence.

The attacker moves laterally.

The attacker steals information.

The attacker attacks recovery systems.

Only then does encryption become the visible final blow.

The August 12 Events Should Trigger Defensive Reviews

Organizations in logistics, healthcare, professional services, manufacturing, and other industries should use these new BlackNevas listings as an opportunity to review their defenses.

A threat intelligence alert is valuable even when it does not involve your own company.

It provides an opportunity to ask whether the same techniques could work against your environment.

Security Teams Should Assume Credentials Will Be Tested

Internet-facing authentication systems should be continuously monitored.

VPN accounts, RDP exposure, MSSQL authentication, cloud identities, and remote-management systems should receive particular attention.

Where possible, unnecessary internet exposure should be removed entirely.

Detection Should Focus on Chains, Not Single Events

One suspicious login may be harmless.

One remote-management installation may be legitimate.

One network scan may be an administrator performing maintenance.

But when these events occur sequentially, the picture changes.

Modern detection must connect the dots.

The Biggest Defensive Advantage Is Time

Every hour gained before encryption matters.

Every suspicious authentication detected early matters.

Every isolated administrative account matters.

Every protected backup matters.

Every segment that prevents lateral movement matters.

Ransomware defense is ultimately a battle over time.

BlackNevas Reinforces That Lesson

The reported August 12 victims are another reminder that ransomware remains an active business threat in 2026.

Companies should not wait for encryption to begin before taking action.

By then, the attacker may already have achieved most of the objectives that make recovery difficult.

Deep Analysis

Linux-Based Threat Hunting

Security teams investigating suspicious Linux systems can begin with basic process and network telemetry.

ps aux --sort=-%cpu | head -25

This command provides a quick view of processes consuming significant CPU resources.

Administrators can then inspect active network connections:

ss -tulpn

Unexpected listening services should be investigated, especially when they appear on systems that should not expose remote administration.

Search for Suspicious Remote Access

A basic process search can help identify unexpected remote-management software:

ps aux | grep -Ei 'mesh|anydesk|atera|teamviewer|screenconnect'

The presence of a legitimate remote-management application is not automatically malicious.

The important question is whether its installation, account ownership, execution time, and network connections match expected administrative activity.

Review Recent Authentication Activity

On systems using systemd journals, defenders can review authentication-related events with:

journalctl --since "24 hours ago" | grep -Ei 'ssh|authentication|failed|accepted'

Repeated failures followed by a successful privileged login deserve immediate investigation.

Inspect New Services

Attackers attempting to maintain persistence may create services.

A quick review can begin with:

systemctl list-unit-files --state=enabled

Unexpected services should be compared against approved software inventories.

Search for Unusual Files

Security teams can examine recently modified executable files with:

find /usr/local/bin /opt /tmp -type f -mtime -2 -perm /111 2>/dev/null

This does not identify ransomware by itself, but it can help uncover suspicious binaries introduced during a recent intrusion.

Check Outbound Connections

Network telemetry should be correlated with host activity.

A sudden outbound connection from a server to an unfamiliar external destination, particularly when combined with archive creation or large file transfers, warrants investigation.

Inspect Archive Creation

Attackers often stage stolen data before exfiltration.

Defenders can look for recently created archives:

find / -type f ( -name ".zip" -o -name ".7z" -o -name ".rar" ) -mtime -1 2>/dev/null

The command is only a hunting aid. Legitimate backup and administrative processes can generate the same file types.

Protect the Investigation

Once ransomware activity is suspected, investigators should avoid unnecessarily modifying compromised systems.

Preserving volatile evidence, collecting logs, isolating affected systems, and maintaining a documented timeline can become crucial for determining the attack path.

Monitor Windows Environments Too

Because BlackNevas has historically targeted Windows environments, defenders should monitor suspicious PowerShell activity, credential-dumping behavior, service creation, remote-management installations, unusual administrative logons, and lateral movement.

Windows event collection should be centralized wherever possible.

Watch for ESXi Activity

Virtualization administrators should monitor unexpected changes to privileged groups and suspicious activity involving ESXi management interfaces.

Any unexpected administrative action involving hypervisors should be investigated rapidly because the potential blast radius can be much larger than a single endpoint.

Final Defensive Assessment

The most effective defense against BlackNevas is layered.

Strong identity controls reduce unauthorized access.

MFA protects accounts.

Segmentation restricts movement.

EDR detects malicious behavior.

Centralized logging preserves evidence.

Network monitoring exposes unusual communications.

Immutable backups protect recovery.

Threat intelligence provides context.

Incident-response preparation converts detection into action.

No individual control guarantees safety.

Together, however, these controls can dramatically reduce the opportunity for a ransomware operator to turn an initial foothold into a company-wide disaster.

✅ Confirmed: BlackNevas Is an Active Ransomware Operation

Security research from AhnLab and Halcyon documents BlackNevas activity dating back to 2024 and links the operation technically to the Trigona ransomware family.

✅ Confirmed: BlackNevas Uses Data Theft Alongside Encryption

Multiple security investigations document BlackNevas as a double-extortion threat, combining encryption with data theft and potential disclosure pressure.

⚠️ Monitoring Report: August 12 Victim Listings

The two August 12 listings are based on the ThreatMon activity information supplied for this article. The listing itself establishes that the organizations were reported as victims in threat-intelligence monitoring, but the available information does not establish the exact intrusion vector, affected systems, stolen data, or whether both organizations experienced the same attack pathway.

Prediction

(+1) BlackNevas Activity Is Likely to Continue

BlackNevas has demonstrated sustained activity across multiple regions and industries. The appearance of additional organizations in August 2026 makes continued targeting likely, particularly against businesses with valuable data and exposed remote-access infrastructure.

(+1) Third-Party IT Access Will Receive More Attention

Security teams are increasingly recognizing that managed service providers and remote-management platforms can become important attack paths. Organizations are likely to strengthen MFA, privileged-access controls, segmentation, and monitoring around external IT accounts.

(+1) Data Exfiltration Detection Will Become More Important

As ransomware operators increasingly steal data before encryption, organizations will place greater emphasis on detecting unusual outbound transfers, suspicious archive creation, and abnormal cloud-storage activity.

(-1) Relying Only on Traditional Antivirus Will Become Less Effective

Human-operated ransomware campaigns can use legitimate administrative tools and stolen credentials, allowing attackers to operate without immediately deploying obvious malware. Organizations relying exclusively on signature-based protection face a growing detection gap.

The Bigger Warning Behind the BlackNevas Listings

The most important message from the August 12 activity is not simply that two more organizations have appeared in a ransomware monitoring report.

It is that the ransomware problem continues to evolve.

BlackNevas demonstrates how attackers can combine stolen credentials, legitimate administration tools, network discovery, data theft, privilege escalation, and encryption into a single coordinated operation.

For organizations, preparation cannot begin after the ransom note appears.

It has to begin when the first suspicious login occurs.

It has to begin when an unknown remote-management tool appears.

It has to begin when an administrator account behaves differently from normal.

And it has to begin before an attacker reaches the backup infrastructure.

Because once the files are encrypted, the battle has already entered its most expensive stage.

The strongest organizations will be the ones that detect the intrusion while the attacker is still moving quietly through the network, before BlackNevas or another ransomware operation gets the opportunity to turn access into devastation.

▶️ Related Video (84% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube