Overview

Platforms: Linux · Windows
Variants: ALPHV · BlackCat · Noberus
Extensions: —
ATT&CK software: BlackCat (S1068)
Initial access: —
Top countries: US · DE · GB · CA · AU
Observed sectors: Healthcare · Government · Technology · Manufacturing · Professional Services
Tracked victims: 700

Attribution

ALPHV VERIFIED
Primary operation name
BlackCat ransomware is also widely tracked under the ALPHV designation.
Noberus VERIFIED
Vendor tracking name
Noberus is another widely used tracking name for the BlackCat ransomware family and operation.

Relationships

Scattered Spider VERIFIED
Reported ransomware affiliate
FBI and CISA reporting states that Scattered Spider actors may have deployed BlackCat/ALPHV ransomware in victim environments.
Storm-0501 VERIFIED
Reported RaaS affiliate
MITRE ATT&CK documents Storm-0501 as having previously been affiliated with BlackCat among several ransomware-as-a-service operations.

Affiliates

No affiliate information available.

Activity

Initial Access

Social engineering and helpdesk impersonation
ALPHV affiliates used phone calls, SMS messages and impersonation of IT or helpdesk personnel to obtain credentials.
Credential theft
Affiliates obtained user credentials and session data through social engineering and adversary-in-the-middle tooling such as Evilginx2.

Recent Observations

ALPHV operation collapses
March 2024
Operational disruption
Following sustained law-enforcement pressure and disruption, ALPHV administrators disappeared and the operation ceased sustained public activity.
Updated ALPHV advisory
February 2024
Government advisory
FBI, CISA and HHS published an updated advisory covering ALPHV BlackCat activity, tooling and tradecraft.
BlackCat 2.0 Sphynx
February 2023
Ransomware update
ALPHV introduced the Sphynx update with improved defense evasion and expanded tooling for affiliates.
BlackCat first observed
November 2021
Operational activity
BlackCat ransomware was first observed operating as a ransomware-as-a-service platform.

TTPs

ATT&CK coverage: 9 techniques · 8 tactics
T1598 Phishing for Information
VERIFIED
Reconnaissance / Credential Access
ALPHV affiliates used SMS messages and phone-based impersonation to obtain credentials.
T1586 Compromise Accounts
VERIFIED
Resource Development
Compromised employee accounts were used to gain access to target environments.
T1219 Remote Access Software
VERIFIED
Command and Control
ALPHV affiliates deployed tools including AnyDesk and Splashtop for remote access.
Show more TTPs (6)
T1557 Adversary-in-the-Middle
VERIFIED
Credential Access
Evilginx2 was used to capture MFA credentials, session cookies and login information.
T1136 Create Account
VERIFIED
Persistence
Affiliates created additional user accounts during compromised-network activity.
T1572 Protocol Tunneling
VERIFIED
Command and Control
Tools such as Ngrok and Plink were used to tunnel traffic through compromised environments.
T1562.001 Impair Defenses
VERIFIED
Defense Evasion
ALPHV affiliates used tools including POORTRY and STONESTOP to terminate security processes.
T1567 Exfiltration Over Web Service
VERIFIED
Exfiltration
Mega and Dropbox were used to transfer and exfiltrate victim data.
T1486 Data Encrypted for Impact
VERIFIED
Impact
BlackCat encrypts Windows and Linux systems and has supported VMware environments.

Victims

ipmaltamira CLAIMED
March 3, 2024 3 tracker sources
Ewig Usa CLAIMED
March 3, 2024 3 tracker sources
SBM & Co CLAIMED
March 1, 2024 3 tracker sources
Petrus Resources Ltd CLAIMED
March 1, 2024 3 tracker sources
Kumagai Gumi Group CLAIMED
March 1, 2024 3 tracker sources
Show more victims (5)
Allan Berger & Associates CLAIMED
February 29, 2024 3 tracker sources
Change Healthcare - Optum - UnitedHealth CONFIRMED
February 28, 2024
verbraucherzentrale hessen CLAIMED
February 27, 2024 3 tracker sources
Electro Marteix CLAIMED
February 27, 2024 3 tracker sources
Angeles Medical Centers CLAIMED
February 26, 2024 3 tracker sources

CVEs

Veritas — Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since: October 2022
Veritas — Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since: October 2022
Veritas — Backup Exec
An ALPHV affiliate was observed exploiting this vulnerability in exposed Backup Exec installations for initial access.
Associated since: October 2022

Infrastructure

ALPHV / BlackCat leak site
Tor-hosted data leak infrastructure used to publish victim information and support multi-extortion operations.
ALPHV / BlackCat negotiation portal
Tor-based infrastructure was operated for communications and ransom negotiations with victims.

Timeline

2024-03
ALPHV operation ends
The administrators disappeared and sustained ALPHV public operations ceased.
2024-02
Operation resumes after disruption
ALPHV affiliates continued ransomware operations following the December 2023 disruption.
2023-12
Law-enforcement disruption
International law-enforcement action disrupted ALPHV infrastructure and enabled recovery capabilities for victims.
Show more events (2)
2023-02
Sphynx update
ALPHV announced BlackCat 2.0 Sphynx with expanded affiliate tooling and improved defense evasion.
2021-11
BlackCat first observed
BlackCat emerged publicly as a Rust-based ransomware-as-a-service operation.

Sources