ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."
BlackCat
BlackCat, also known as ALPHV and Noberus, is a file-encrypting ransomware family associated with a ransomware-as-a-service operation.
BlackCat
Family profile
BlackCat, also known as ALPHV and Noberus, is a file-encrypting ransomware family associated with a ransomware-as-a-service operation. Its operators and affiliates combine encryption with data theft and threats to publish stolen information. The operation has used searchable leak-site interfaces and publicly accessible victim-data excerpts to increase extortion pressure, sometimes adding distributed denial-of-service threats. BlackCat campaigns have affected businesses across sectors, including healthcare, where attacks can disrupt critical services and financial operations.
BlackCat-associated intrusions include exploitation of CVE-2023-0669 in Fortra GoAnywhere MFT. Operators have also abused Active Directory Group Policy Objects to create scheduled tasks and distribute ransomware across Windows environments. Associated tooling includes ExMatter for data exfiltration. UNC3944, also known as Scattered Spider, has deployed ALPHV against VMware ESXi datastores, encrypting virtual-machine infrastructure and sometimes destroying evidence of its own intrusion activity. This affiliate uses help-desk impersonation and SMS phishing to compromise privileged accounts and bypass multifactor authentication. BlackCat's affiliate model allows intrusion methods and supporting tools to vary between campaigns.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
18 named in public reportingRoyal having a close working relationship with BlackCat and continuing to borrow its loader.
At-Bay’s Cyber Research team confirmed that BlackCat has successfully exploited the GoAnywhere MFT vulnerability and attacked a U.S. business in February 2023.
Mandiant has observed UNC3944 deploying ALPHV ransomware against the Virtual Machine File Systems, on the ESXI hypervisors themselves, to cause destructive actions inside of an environment.
Scattered Spider also established ransomware-as-a-service operations, including ALPHV/BlackCat, DragonForce, and Qilin, to monetize access through encryption and extortion.
New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
BlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.
ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.
DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.
Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Exploited software
Vulnerabilities linked to BlackCat
19 CVEsMITRE ATT&CK
BlackCat in ATT&CK
101 distinct techniquesTechniques
101 techniquesReporting
Research mentioning BlackCat
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Ransomware Group clop Hits: 9ALTITUDES.COM
Ransomware Group clop Hits: WATERLANDPE.COM
Ransomware Group clop Hits: NETPOWER.COM
Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)
Ransomware Group clop Hits: IRCO.COM
Ransomware Group clop Hits: LARGAN.COM.TW
Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX
Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.