Skip to content

BlackCat

BlackCat, also known as ALPHV and Noberus, is a file-encrypting ransomware family associated with a ransomware-as-a-service operation.

BlackCat

Family profile

BlackCat, also known as ALPHV and Noberus, is a file-encrypting ransomware family associated with a ransomware-as-a-service operation. Its operators and affiliates combine encryption with data theft and threats to publish stolen information. The operation has used searchable leak-site interfaces and publicly accessible victim-data excerpts to increase extortion pressure, sometimes adding distributed denial-of-service threats. BlackCat campaigns have affected businesses across sectors, including healthcare, where attacks can disrupt critical services and financial operations.

BlackCat-associated intrusions include exploitation of CVE-2023-0669 in Fortra GoAnywhere MFT. Operators have also abused Active Directory Group Policy Objects to create scheduled tasks and distribute ransomware across Windows environments. Associated tooling includes ExMatter for data exfiltration. UNC3944, also known as Scattered Spider, has deployed ALPHV against VMware ESXi datastores, encrypting virtual-machine infrastructure and sometimes destroying evidence of its own intrusion activity. This affiliate uses help-desk impersonation and SMS phishing to compromise privileged accounts and bypass multifactor authentication. BlackCat's affiliate model allows intrusion methods and supporting tools to vary between campaigns.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

18 named in public reporting
ShadowSyndicate

ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."

Ke3chang

Royal having a close working relationship with BlackCat and continuing to borrow its loader.

BlackCat

At-Bay’s Cyber Research team confirmed that BlackCat has successfully exploited the GoAnywhere MFT vulnerability and attacked a U.S. business in February 2023.

Scattered Spider

Mandiant has observed UNC3944 deploying ALPHV ransomware against the Virtual Machine File Systems, on the ESXI hypervisors themselves, to cause destructive actions inside of an environment.

Scattered Lapsus$ Hunters

Scattered Spider also established ransomware-as-a-service operations, including ALPHV/BlackCat, DragonForce, and Qilin, to monetize access through encryption and extortion.

Velvet Tempest

New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"

fin12

BlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.

FIN7

ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.

AdverCRow

The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.

Vanilla Tempest

Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.

Ambitious Scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

GOLD HARVEST

GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.

WIZARD SPIDER

DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.

Nitrogen

Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

FIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

Cicada3301

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

UNC4466

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

Exploited software

Vulnerabilities linked to BlackCat

19 CVEs

MITRE ATT&CK

BlackCat in ATT&CK

101 distinct techniques

Techniques

101 techniques
T1083 File and Directory Discovery T1087.002 Domain Account T1059.003 Windows Command Shell T1134 Access Token Manipulation T1069.002 Domain Groups T1486 Data Encrypted for Impact T1112 Modify Registry T1680 Local Storage Discovery T1685.005 Clear Windows Event Logs T1561.001 Disk Content Wipe T1135 Network Share Discovery T1570 Lateral Tool Transfer T1490 Inhibit System Recovery T1018 Remote System Discovery T1489 Service Stop T1033 System Owner/User Discovery T1082 System Information Discovery T1222.001 Windows Permissions T1548.002 Bypass User Account Control T1491.001 Internal Defacement T1047 Windows Management Instrumentation T1498 Network Denial of Service T1657 Financial Theft T1120 Peripheral Device Discovery T1057 Process Discovery T1016 System Network Configuration Discovery T1559.001 Component Object Model T1007 System Service Discovery T1569.002 Service Execution T1559 Inter-Process Communication T1068 Exploitation for Privilege Escalation T1021 Remote Services T1567.002 Exfiltration to Cloud Storage T1110 Brute Force T1078 Valid Accounts T1552.001 Credentials In Files T1587.001 Malware T1046 Network Service Discovery T1529 System Shutdown/Reboot T1070.004 File Deletion T1222 File and Directory Permissions Modification T1133 External Remote Services T1484.001 Group Policy Modification T1566 Phishing T1036 Masquerading T1190 Exploit Public-Facing Application T1021.002 SMB/Windows Admin Shares T1189 Drive-by Compromise T1059.001 PowerShell T1048 Exfiltration Over Alternative Protocol T1566.001 Spearphishing Attachment T1583.008 Malvertising T1059 Command and Scripting Interpreter T1485 Data Destruction T1685 Disable or Modify Tools T1053 Scheduled Task/Job T1021.004 SSH T1041 Exfiltration Over C2 Channel T1505.003 Web Shell T1074 Data Staged T1491 Defacement T1055 Process Injection T1059.004 Unix Shell T1543.003 Windows Service T1560.001 Archive via Utility T1578 Modify Cloud Compute Infrastructure T1003.001 LSASS Memory T1003 OS Credential Dumping T1560 Archive Collected Data T1497 Virtualization/Sandbox Evasion T1105 Ingress Tool Transfer T1012 Query Registry T1021.001 Remote Desktop Protocol T1071 Application Layer Protocol T1567 Exfiltration Over Web Service T1537 Transfer Data to Cloud Account T1573 Encrypted Channel T1005 Data from Local System T1574.011 Services Registry Permissions Weakness T1622 Debugger Evasion T1027 Obfuscated Files or Information T1202 Indirect Command Execution T1027.002 Software Packing T1140 Deobfuscate/Decode Files or Information T1499 Endpoint Denial of Service T1550.002 Pass the Hash T1684.001 Impersonation T1565.001 Stored Data Manipulation T1592.001 Hardware T1598.004 Spearphishing Voice T1568 Dynamic Resolution T1496 Resource Hijacking T1598 Phishing for Information T1020 Automated Exfiltration T1621 Multi-Factor Authentication Request Generation T1213 Data from Information Repositories T1199 Trusted Relationship T1571 Non-Standard Port T1589.001 Credentials T1087 Account Discovery T1566.004 Spearphishing Voice

Reporting

Research mentioning BlackCat

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Aug 12
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX

Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.