~/f4n6 $ grep -r "Ransomware: nova named SistNet (IT)" ./investigations/ --include="*.md"

Ransomware: nova named SistNet (IT)

Jeff Davies 25 Jul 2026 4 min read

1. Executive summary

On 25 July 2026, the ransomware actor "nova" publicly claimed a compromise of SistNet (sistnet.it), a division of Sistemi Tre s.r.l. operating in the Italian ICT services market. The actor claims to have exfiltrated stolen data and provided a file-tree and samples to the victim, alongside a decrypt sample, indicating a double-extortion model combining encryption with data theft. Attribution to the "nova" group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data — and the technical detail of the compromise is minimal, sourced solely from the ransomware leak portal. EMEA financial services clients should treat this as a potential supply-chain concern if SistNet or Sistemi Tre s.r.l. provides ICT or security services to their environment.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The available facts describe a claimed compromise of a third-party ICT provider, but there is no confirmed impact on a regulated financial entity, no confirmed major-incident threshold breach, and no verified contractual relationship triggering third-party risk obligations. If a client confirms SistNet as an ICT third-party provider, DORA Art. 28 (ICT third-party risk — general principles) and DORA Art. 30 (key contractual provisions with ICT third-party providers) would engage — but that relationship is not established in the source material.

3. Technical analysis & attack chain

The source material is a ransomware leak-site entry. No technical attack-chain detail, initial access vector, CVE, malware sample, or TTP is provided. The following is limited to what the source states:

  1. Victim identification: SistNet (sistnet.it), a division of Sistemi Tre s.r.l., providing ICT solutions including EDR-X antivirus, networking, unified communication, cloud backup, and email services to SMEs.
  2. Actor claim: The group "nova" claims to have exfiltrated data from SistNet. The actor states it has provided a "tree and samples from stolen data" and a "decrypt sample" to the company upon contact with their support department — consistent with a double-extortion ransomware model (encryption + data exfiltration).
  3. Compromised assets (single-sourced; verify before enforcement): Hudson Rock data indexed by Ransomware.live reports 1 compromised employee, 3 compromised users, 0 third-party employee credentials, and 15 external attack-surface findings for the victim's domain. This data is sourced from a third-party infostealer-intelligence platform and has not been independently corroborated. It may indicate prior infostealer infections on employee or user machines, which could represent an initial-access vector, but this is inferential.

Confidence caveat: All claims in this section rest on a single source (Ransomware.live / Hudson Rock). No law-enforcement confirmation, victim disclosure, or independent security-vendor report is available. Attribution to "nova" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item.

4. Mitigation & containment

No technical indicators, malware samples, or vulnerability details are available from the source to support specific containment actions. The following are process-level steps:

P1 — within 24h

  • Determine whether your organisation has a direct vendor relationship with SistNet / Sistemi Tre s.r.l. for ICT, security (EDR-X), networking, cloud backup, or email services. If yes, initiate vendor incident-response enquiry: confirm whether the breach is real, what data was accessed, and whether any of your data or credentials are affected.
  • If SistNet provides managed services with access to your environment, review and restrict that access pending confirmation. Disable integrations or remote-access accounts if feasible.

P2 — within 72h

  • If a confirmed vendor relationship exists and the breach is validated, assess whether any of your data, credentials, or systems were exposed. Rotate any credentials shared with or managed by SistNet.
  • Review logs for any anomalous activity originating from SistNet-managed infrastructure or IP ranges.

P3 — within 7 days

  • If SistNet is a confirmed ICT third-party provider, document the incident against your third-party risk register and assess contractual notification obligations.
  • Monitor the Ransomware.live listing and any subsequent disclosures for updated indicators or leaked data.

5. Indicators of compromise

No indicators of compromise available in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
Infostealer-related credential compromise on SistNet employee/user machines (1 employee, 3 users reported) Hudson Rock infostealer intelligence platform; not directly observable in client environment Low — single-sourced, uncorroborated
Data exfiltration from SistNet environment Victim network egress logs (if SistNet is a managed-service provider with access to client environment) Low — actor claim only, no technical detail

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Ransomware: nova named SistNet (IT)," https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, published 2026-07-25.
  • Ransomware.live, "Ransomware: nova named Hynet (GB)" (corpus context for nova group MO), https://www.ransomware.live/id/SHluZXRAbm92YQ==, accessed 2026-07-25.
  • Hudson Rock / Ransomware.live external data for victim SistNet (compromised employee/user counts, attack surface), https://www.ransomware.live/id/U2lzdE5ldEBub3Zh, accessed 2026-07-25.

8. Adverse Trace position

This is a low-confidence, single-sourced ransomware claim against an Italian ICT services provider. The actor "nova" has no confirmed MITRE ATT&CK profile and the attribution is unconfirmed. No CVE, CVSS, or CISA-KEV data applies. The primary risk to EMEA financial services clients is supply-chain exposure: SistNet provides managed security (EDR-X), cloud backup, and networking services to SMEs, and any client using SistNet as an ICT third-party provider should treat this as a potential third-party incident requiring vendor enquiry and access review. We will monitor for corroborating reporting, leaked indicators, or law-enforcement confirmation and update this advisory if the claim is validated or technical indicators emerge.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies