> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: nova named SistNet (IT)
- URL: https://f4n6.co.uk/security-feed/ransomware-nova-named-sistnet-it/
- Published: 2026-07-25T17:38:32.000Z
- Updated: 2026-07-25T17:38:32.000Z
- Author: Jeff Davies
- Tags: #security-feed, nova

## 1\. Executive summary

On 25 July 2026, the ransomware actor "nova" publicly claimed a compromise of SistNet (sistnet.it), a division of Sistemi Tre s.r.l. operating in the Italian ICT services market. The actor claims to have exfiltrated stolen data and provided a file-tree and samples to the victim, alongside a decrypt sample, indicating a double-extortion model combining encryption with data theft. Attribution to the "nova" group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data — and the technical detail of the compromise is minimal, sourced solely from the ransomware leak portal. EMEA financial services clients should treat this as a potential supply-chain concern if SistNet or Sistemi Tre s.r.l. provides ICT or security services to their environment.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The available facts describe a claimed compromise of a third-party ICT provider, but there is no confirmed impact on a regulated financial entity, no confirmed major-incident threshold breach, and no verified contractual relationship triggering third-party risk obligations. If a client confirms SistNet as an ICT third-party provider, DORA Art. 28 (ICT third-party risk — general principles) and DORA Art. 30 (key contractual provisions with ICT third-party providers) would engage — but that relationship is not established in the source material.

## 3\. Technical analysis & attack chain

The source material is a ransomware leak-site entry. No technical attack-chain detail, initial access vector, CVE, malware sample, or TTP is provided. The following is limited to what the source states:

1. **Victim identification:** SistNet (sistnet.it), a division of Sistemi Tre s.r.l., providing ICT solutions including EDR-X antivirus, networking, unified communication, cloud backup, and email services to SMEs.
2. **Actor claim:** The group "nova" claims to have exfiltrated data from SistNet. The actor states it has provided a "tree and samples from stolen data" and a "decrypt sample" to the company upon contact with their support department — consistent with a double-extortion ransomware model (encryption + data exfiltration).
3. **Compromised assets (single-sourced; verify before enforcement):** Hudson Rock data indexed by Ransomware.live reports 1 compromised employee, 3 compromised users, 0 third-party employee credentials, and 15 external attack-surface findings for the victim's domain. This data is sourced from a third-party infostealer-intelligence platform and has not been independently corroborated. It may indicate prior infostealer infections on employee or user machines, which could represent an initial-access vector, but this is inferential.

**Confidence caveat:** All claims in this section rest on a single source (Ransomware.live / Hudson Rock). No law-enforcement confirmation, victim disclosure, or independent security-vendor report is available. Attribution to "nova" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item.

## 4\. Mitigation & containment

No technical indicators, malware samples, or vulnerability details are available from the source to support specific containment actions. The following are process-level steps:

### P1 — within 24h

- Determine whether your organisation has a direct vendor relationship with SistNet / Sistemi Tre s.r.l. for ICT, security (EDR-X), networking, cloud backup, or email services. If yes, initiate vendor incident-response enquiry: confirm whether the breach is real, what data was accessed, and whether any of your data or credentials are affected.
- If SistNet provides managed services with access to your environment, review and restrict that access pending confirmation. Disable integrations or remote-access accounts if feasible.

### P2 — within 72h

- If a confirmed vendor relationship exists and the breach is validated, assess whether any of your data, credentials, or systems were exposed. Rotate any credentials shared with or managed by SistNet.
- Review logs for any anomalous activity originating from SistNet-managed infrastructure or IP ranges.

### P3 — within 7 days

- If SistNet is a confirmed ICT third-party provider, document the incident against your third-party risk register and assess contractual notification obligations.
- Monitor the Ransomware.live listing and any subsequent disclosures for updated indicators or leaked data.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

### Behavioural indicators

| Behaviour                                                                                                  | Where to observe                                                                                        | Confidence                                  |
| ---------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| Infostealer-related credential compromise on SistNet employee/user machines (1 employee, 3 users reported) | Hudson Rock infostealer intelligence platform; not directly observable in client environment            | Low — single-sourced, uncorroborated        |
| Data exfiltration from SistNet environment                                                                 | Victim network egress logs (if SistNet is a managed-service provider with access to client environment) | Low — actor claim only, no technical detail |

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- Ransomware.live, "Ransomware: nova named SistNet (IT)," https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, published 2026-07-25.
- Ransomware.live, "Ransomware: nova named Hynet (GB)" (corpus context for nova group MO), https://www.ransomware.live/id/SHluZXRAbm92YQ==, accessed 2026-07-25.
- Hudson Rock / Ransomware.live external data for victim SistNet (compromised employee/user counts, attack surface), https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, accessed 2026-07-25.

## 8\. Adverse Trace position

This is a low-confidence, single-sourced ransomware claim against an Italian ICT services provider. The actor "nova" has no confirmed MITRE ATT&CK profile and the attribution is unconfirmed. No CVE, CVSS, or CISA-KEV data applies. The primary risk to EMEA financial services clients is supply-chain exposure: SistNet provides managed security (EDR-X), cloud backup, and networking services to SMEs, and any client using SistNet as an ICT third-party provider should treat this as a potential third-party incident requiring vendor enquiry and access review. We will monitor for corroborating reporting, leaked indicators, or law-enforcement confirmation and update this advisory if the claim is validated or technical indicators emerge.

---

[Read the original source →](https://www.ransomware.live/id/U2lzdE5ldEBub3Zh?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*