ALPHV, also known as BlackCat and associated with the Noberus name, was a prominent ransomware-as-a-service operation that emerged in late 2021 and became one of the most disruptive cybercriminal enterprises targeting organizations worldwide. The operation used an affiliate model in which core operators provided ransomware, extortion infrastructure, and negotiation platforms to affiliates, who conducted intrusions, stole data, encrypted systems, and demanded cryptocurrency payments. Affiliates typically shared a portion of ransom proceeds with the administrators. BlackCat has been linked to attacks against more than 1,000 organizations and was associated with hundreds of millions of dollars in ransom payments before major law-enforcement disruption in late 2023. BlackCat targeted a wide range of sectors, including healthcare, financial services, hospitality, retail, legal services, education, school districts, medical technology, nonprofits, and critical infrastructure-related organizations. The group was known for combining data theft with encryption and for using leak-site pressure and direct negotiation tactics to maximize extortion. Reporting has also associated the group with exploitation of high-impact vulnerabilities during mass exploitation waves, including activity observed around Log4Shell. Operationally, BlackCat followed the standard ransomware-as-a-service pattern of initial compromise, data exfiltration, encryption, and multi-stage extortion. The group maintained dedicated victim communication and payment infrastructure and enabled affiliates to threaten publication of stolen data if victims refused to pay. BlackCat negotiators were noted for adapting ransom demands based on victim-specific financial and insurance information when available. In a notable insider-enabled extortion case, trusted incident-response and ransomware-negotiation professionals secretly provided confidential victim negotiation positions and insurance details to BlackCat operators and later acted as affiliates themselves, illustrating the group’s willingness to exploit insider access in addition to conventional intrusion tradecraft. BlackCat is widely regarded as a financially motivated cybercriminal organization rather than a nation-state actor. The operation was disrupted by law enforcement in December 2023, including seizure of parts of its infrastructure and deployment of a decryption capability that helped victims recover without payment. Subsequent reporting described the group as defunct or severely degraded, and it has also been associated with an exit scam after the disruption. Known aliases include ALPHV and BlackCat; Noberus has also been linked to the operation in some reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware groups that exploited Log4Shell in incident response cases.
A ransomware operation that received insider negotiation intelligence from a DigitalMint negotiator and later had affiliates, including the conspirators, deploy BlackCat directly against additional victims for extortion payments.
Mentioned only in a related-articles link title; no substantive discussion in the content.
Ransomware group whose members received confidential victim negotiation data from a DigitalMint negotiator, used it to maximize ransom demands, and later partnered with insiders who helped attack organizations by breaching corporate networks, stealing data, and deploying ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.