BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation that emerged as one of the most prominent extortion threats of the early 2020s. The group provides file-encrypting malware and an extortion platform to affiliates, who conduct intrusions and share a portion of ransom proceeds with the core operators. BlackCat has been linked to more than 1,000 victims and hundreds of millions of dollars in ransom payments through late 2023.
BlackCat operations are characterized by double extortion: affiliates steal data from victim environments and then deploy ransomware to encrypt systems while threatening to leak stolen information if payment is not made. Reported affiliate activity includes breaching corporate networks, conducting post-compromise operations, exfiltrating data, and deploying the encryptor against organizations in the United States and other regions. Victims have included organizations in healthcare, financial services, retail, hospitality, nonprofit, and medical-device sectors, among others. The operation became particularly notorious for aggressive pressure tactics, including public leak-site extortion.
The service follows the standard ransomware affiliate model in which independent operators obtain access to victim networks and use BlackCat’s malware and negotiation infrastructure in exchange for a revenue share paid to the administrators. Public reporting and court records also show that BlackCat affiliates included insiders and cybersecurity professionals who abused trusted access to support extortion and ransomware deployment.
Law enforcement disrupted parts of the BlackCat infrastructure in December 2023, seized websites associated with the operation, and developed a decryption capability that helped victims recover systems without paying. Despite that disruption, BlackCat remained a major reference point in discussions of modern ransomware tradecraft and the risks posed by mature affiliate-driven extortion ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–1709 is an Authentication Bypass Vulnerability in ConnectWise ScreenConnect instances caused by inadequate validation of URLs and insufficient access control, and it is a high severity vulnerability with confirmed real world exploitation by the BlackCat/Alphv ransomware gang and the Kimsuky group.
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
Afin de se latéraliser, les opérateurs du MOA ont tenté, sans succès, d’exploiter les vulnérabilités PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), puis ZeroLogon (CVE-2020-1472) via l’outil Mimikatz.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
The BlackCat (or ALPHV) ransomware came to prominence in late 2021 and is the first known ransomware to be written in the Rust programming language.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Court filings state that Martino shared those affiliate credentials with Kevin Martin and Ryan Goldberg, both cybersecurity professionals.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
the FBI developed a decryption tool that allowed FBI field offices across the country and law enforcement partners around the world to offer hundreds of victims the capability of restoring their systems
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
Its developers supplied malware and infrastructure to affiliates, who conducted network intrusions, stole data, encrypted systems, and demanded cryptocurrency payments.
In February 2024, ALPHV/BlackCat broke into Change Healthcare, one of the largest healthcare payment processors in the US, and stole over six terabytes of health and financial data.
one conversation took place through the standard negotiation interface used during ransomware incidents, he also relied on an intermediary chat feature within the group's panel and the encrypted messaging application Tox to exchange information directly with the attackers outside the victims' view.
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. | Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain.
248 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family/group that became prominent after earlier groups were disrupted, also known as ALPHV.
BlackCat is described as a ransomware-as-a-service platform that provides malware and extortion infrastructure to affiliates, who compromise victim organizations, deploy the ransomware, and share a percentage of ransom payments with the administrators.
Referenced for comparison to INC Ransom’s operating model and Rust adoption, not as the subject of the report.
Mentioned only in a related-articles section, not discussed in the article body.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.