ambitious_scorpius
Ambitious Scorpius is the cluster name used for the operators/distributors of the ALPHV/BlackCat ransomware-as-a-service program. ALPHV and BlackCat are explicitly associated with Ambitious Scorpius in the provided content, and affiliates of the group have been observed using ADRecon in multiple intrusions, suggesting repeated use of LDAP-based Active Directory reconnaissance as part of their playbook. The group was described as the second-most prolific ransomware group in 2023 leak site data. In 2024, its activity declined following FBI disruption in December 2023. By March 2024, Ambitious Scorpius reportedly conducted an exit scam by selling the ALPHV/BlackCat source code and falsely claiming that the FBI had seized its site and infrastructure. Known alias from the content: ALPHV, BlackCat.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the group associated with the ALPHV ransomware-as-a-service program that Muddled Libra has partnered with.
Ransomware operators or affiliates associated with BlackCat/ALPHV that used ADRecon to enumerate Active Directory environments as part of intrusion activity.
Previously a leading ransomware group distributing ALPHV/BlackCat, Ambitious Scorpius ceased operations after law enforcement disruption, conducting an exit scam and selling its ransomware source code.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.