Nevada
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Nevada is a threat actor that operates under the alias Nevada and has been publicly linked to China. The group first came to attention in early February 2023 when it claimed responsibility for a ransomware attack that affected several hosting providers, including Ikoula and OVH, and disrupted the broadcast services of the French radio station Fréquence 3. According to the victim’s press release, the attack encrypted thousands of virtual machines and demanded a ransom of approximately €45,000 in bitcoin for data recovery. No further aliases or alternative names for the actor have been documented in the available sources.
The Nevada group’s observed activity targeted the hosting and media sectors, specifically compromising infrastructure that supported both FM and web radio transmissions. The ransomware incident caused a thirty‑minute interruption of the FM broadcast before backup systems restored service, while web radio platforms experienced more severe and prolonged outages that were expected to last several days. The explicit demand for a monetary payment indicates a financially motivated objective, with no public evidence pointing to espionage, sabotage, or ideological goals as the primary driver of the attack. The disruption to broadcast services appears to be a consequence of the ransomware encryption rather than a stated strategic aim.
In terms of tactics, the only confirmed technique associated with Nevada is the deployment of ransomware, although the specific malware family or variant has not been identified in the reporting. The sources do not describe initial access vectors, lateral movement tools, or post‑exploitation utilities used by the group. Attribution to Nevada rests solely on the group’s self‑claim and the attribution by Le Monde Informatique cited in the press release; no state sponsorship, criminal consortium affiliation, or additional corroborating evidence has been presented. The February 2023 ransomware operation against multiple hosting providers remains the sole publicly reported campaign that can be directly linked to the Nevada actor.
Incidents
Attributed incidents are available to members.
1 incident