Overview
Platforms:
Linux · Windows
Variants:
ALPHV · BlackCat · Noberus
Extensions:
—
ATT&CK software:
BlackCat (S1068)
Initial access:
—
Top countries:
US · DE · GB · CA · AU
Observed sectors:
Healthcare · Government · Technology · Manufacturing · Professional Services
Tracked victims:
700
Attribution
ALPHV
VERIFIED
Primary operation name
BlackCat ransomware is also widely tracked under the ALPHV designation.
Noberus
VERIFIED
Vendor tracking name
Noberus is another widely used tracking name for the BlackCat ransomware family and operation.
Relationships
Scattered Spider
VERIFIED
Reported ransomware affiliate
FBI and CISA reporting states that Scattered Spider actors may have deployed BlackCat/ALPHV ransomware in victim environments.
Storm-0501
VERIFIED
Reported RaaS affiliate
MITRE ATT&CK documents Storm-0501 as having previously been affiliated with BlackCat among several ransomware-as-a-service operations.
Affiliates
No affiliate information available.
Activity
Initial Access
Social engineering and helpdesk impersonation
ALPHV affiliates used phone calls, SMS messages and impersonation of IT or helpdesk personnel to obtain credentials.
Credential theft
Affiliates obtained user credentials and session data through social engineering and adversary-in-the-middle tooling such as Evilginx2.
Recent Observations
ALPHV operation collapses
March 2024
Operational disruption
Following sustained law-enforcement pressure and disruption, ALPHV administrators disappeared and the operation ceased sustained public activity.
Updated ALPHV advisory
February 2024
Government advisory
FBI, CISA and HHS published an updated advisory covering ALPHV BlackCat activity, tooling and tradecraft.
BlackCat 2.0 Sphynx
February 2023
Ransomware update
ALPHV introduced the Sphynx update with improved defense evasion and expanded tooling for affiliates.
BlackCat first observed
November 2021
Operational activity
BlackCat ransomware was first observed operating as a ransomware-as-a-service platform.
TTPs
ATT&CK coverage:
9 techniques
· 8 tactics
T1598
Phishing for Information
VERIFIEDReconnaissance / Credential Access
ALPHV affiliates used SMS messages and phone-based impersonation to obtain credentials.
T1586
Compromise Accounts
VERIFIEDResource Development
Compromised employee accounts were used to gain access to target environments.
T1219
Remote Access Software
VERIFIEDCommand and Control
ALPHV affiliates deployed tools including AnyDesk and Splashtop for remote access.
Show more TTPs (6)
T1557
Adversary-in-the-Middle
VERIFIEDCredential Access
Evilginx2 was used to capture MFA credentials, session cookies and login information.
T1136
Create Account
VERIFIEDPersistence
Affiliates created additional user accounts during compromised-network activity.
T1572
Protocol Tunneling
VERIFIEDCommand and Control
Tools such as Ngrok and Plink were used to tunnel traffic through compromised environments.
T1562.001
Impair Defenses
VERIFIEDDefense Evasion
ALPHV affiliates used tools including POORTRY and STONESTOP to terminate security processes.
T1567
Exfiltration Over Web Service
VERIFIEDExfiltration
Mega and Dropbox were used to transfer and exfiltrate victim data.
T1486
Data Encrypted for Impact
VERIFIEDImpact
BlackCat encrypts Windows and Linux systems and has supported VMware environments.
Victims
ipmaltamira
CLAIMED
Ewig Usa
CLAIMED
SBM & Co
CLAIMED
Petrus Resources Ltd
CLAIMED
Kumagai Gumi Group
CLAIMED
Show more victims (5)
Allan Berger & Associates
CLAIMED
Change Healthcare - Optum - UnitedHealth
CONFIRMED
verbraucherzentrale hessen
CLAIMED
Electro Marteix
CLAIMED
Angeles Medical Centers
CLAIMED
CVEs
Veritas
— Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since:
October 2022
Veritas
— Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since:
October 2022
Veritas
— Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since:
October 2022
Infrastructure
ALPHV / BlackCat leak site
Tor-hosted data leak infrastructure used to publish victim information and support multi-extortion operations.
ALPHV / BlackCat negotiation portal
Tor-based infrastructure was operated for communications and ransom negotiations with victims.
Timeline
2024-03
ALPHV operation ends
The administrators disappeared and sustained ALPHV public operations ceased.
2024-02
Operation resumes after disruption
ALPHV affiliates continued ransomware operations following the December 2023 disruption.
2023-12
Law-enforcement disruption
International law-enforcement action disrupted ALPHV infrastructure and enabled recovery capabilities for victims.
Show more events (2)
2023-02
Sphynx update
ALPHV announced BlackCat 2.0 Sphynx with expanded affiliate tooling and improved defense evasion.
2021-11
BlackCat first observed
BlackCat emerged publicly as a Rust-based ransomware-as-a-service operation.
Sources
Show more sources (10)
ALPHV Ransomware Affiliate Targets Vulnerable Backup Installations to Gain Initial Access
Mandiant / Google Cloud
Justice Department Disrupts Prolific ALPHV/BlackCat Ransomware Variant
U.S. Department of Justice
Threat Assessment: BlackCat Ransomware
Palo Alto Networks Unit 42
UnitedHealth Group Updates on Change Healthcare Cyberattack
UnitedHealth Group
ALPHV/Blackcat Ransomware Attacks on the Healthcare and Public Health Sector
CISA (Cybersecurity & Infrastructure Security Agency)