ALPHV, commonly known as BlackCat, was a prominent ransomware-as-a-service operation active from 2021 through major law-enforcement disruption in late 2023, with subsequent activity and affiliate-linked incidents continuing into 2024. The group is widely assessed as a Russian-speaking cybercriminal enterprise rather than a state-sponsored actor. Known aliases include ALPHV, BlackCat, Noberus, and related naming variants; some reporting also associates the Embargo name with BlackCat-linked activity, but that relationship is not sufficiently established to treat Embargo as a confirmed alias. BlackCat operated a mature affiliate model in which core administrators maintained the ransomware platform, extortion infrastructure, and negotiation processes while affiliates conducted intrusions and deployed payloads. Affiliates typically retained the majority of ransom proceeds and paid a share to the operators. The group used double extortion as a standard model, combining data theft with encryption and threatening publication of stolen information through leak-site operations when victims refused to pay. The operation targeted a broad range of sectors worldwide, with especially notable impact on healthcare, financial services, retail, hospitality, manufacturing, nonprofits, and critical infrastructure. One of the most consequential publicly reported incidents attributed to ALPHV/BlackCat was the 2024 attack on Change Healthcare, which caused major disruption to healthcare claims processing in the United States and involved large-scale theft of sensitive health and financial data. BlackCat has been linked to exploitation of exposed remote services, credential abuse, and opportunistic use of high-impact vulnerabilities. Reporting has associated the group with exploitation activity following Log4Shell disclosure and with common ransomware tradecraft such as lateral movement, privilege escalation, data exfiltration, remote administration tooling, and abuse of legitimate Windows utilities and remote access mechanisms including RDP. Like other leading ransomware crews of its era, the group relied heavily on affiliates and adaptable intrusion playbooks rather than a single fixed initial-access method. The group became notable not only for the scale of its extortion activity but also for the breadth of its criminal ecosystem. U.S. authorities linked BlackCat to more than 1,000 victim organizations and at least hundreds of millions of dollars in ransom payments through September 2023. Court cases in the United States later showed that BlackCat affiliates and negotiators benefited from insider assistance from cybersecurity professionals who leaked confidential victim negotiation information and, in some cases, directly participated as affiliates in ransomware attacks. In December 2023, law enforcement disrupted parts of BlackCat’s infrastructure, seized control of elements of its online presence, and released a decryptor that helped some victims recover without paying. Despite that disruption, BlackCat remained operationally significant in subsequent reporting, illustrating the resilience of the ransomware-as-a-service model and the persistence of affiliate networks even after infrastructure takedowns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group that rose after earlier major groups were disrupted, before later facing its own takedown.
Ransomware group responsible for the February 2024 intrusion into Change Healthcare, stealing over six terabytes of health and financial data and causing major disruption to US medical claims processing.
Operates a ransomware-as-a-service platform whose affiliates compromise victim networks, deploy ransomware, and use extortion infrastructure while sharing ransom proceeds with the group's administrators.
Mentioned only as a previously linked Russia-aligned threat actor in background context about RansomHouse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.