Skip to content

BlackCat

BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation that emerged as one of the most prominent extortion threats of the early 2020s.

Profile source: Mallory opens in a new tab

BlackCat

Family profile

BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation that emerged as one of the most prominent extortion threats of the early 2020s. The group provides file-encrypting malware and an extortion platform to affiliates, who conduct intrusions and share a portion of ransom proceeds with the core operators. BlackCat has been linked to more than 1,000 victims and hundreds of millions of dollars in ransom payments through late 2023.

BlackCat operations are characterized by double extortion: affiliates steal data from victim environments and then deploy ransomware to encrypt systems while threatening to leak stolen information if payment is not made. Reported affiliate activity includes breaching corporate networks, conducting post-compromise operations, exfiltrating data, and deploying the encryptor against organizations in the United States and other regions. Victims have included organizations in healthcare, financial services, retail, hospitality, nonprofit, and medical-device sectors, among others. The operation became particularly notorious for aggressive pressure tactics, including public leak-site extortion.

The service follows the standard ransomware affiliate model in which independent operators obtain access to victim networks and use BlackCat’s malware and negotiation infrastructure in exchange for a revenue share paid to the administrators. Public reporting and court records also show that BlackCat affiliates included insiders and cybersecurity professionals who abused trusted access to support extortion and ransomware deployment.

Law enforcement disrupted parts of the BlackCat infrastructure in December 2023, seized websites associated with the operation, and developed a decryption capability that helped victims recover systems without paying. Despite that disruption, BlackCat remained a major reference point in discussions of modern ransomware tradecraft and the risks posed by mature affiliate-driven extortion ecosystems.

Capabilities

  • Exfiltration
  • Extortion
  • Lateral Movement
  • Post Exploitation

Operational record

1
YARA rules
4
Ransom notes
4
Leak sites
0 available

Reported operators

Threat actors

14 named in public reporting
Scattered Spider

Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.

AdverCRow

The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.

Vanilla Tempest

Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.

BlackCat

The BlackCat (or ALPHV) ransomware came to prominence in late 2021 and is the first known ransomware to be written in the Rust programming language.

ambitious_scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

GOLD HARVEST

GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.

WIZARD SPIDER

DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.

Velvet Tempest

DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.

Nitrogen

Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

ShadowSyndicate

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

FIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

Cicada3301

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

UNC4466

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

Exploited software

Vulnerabilities linked to BlackCat

17 CVEs

MITRE ATT&CK

BlackCat in ATT&CK

89 distinct techniques

Techniques

89 techniques
T1486 Data Encrypted for Impact T1537 Transfer Data to Cloud Account T1567 Exfiltration Over Web Service T1573 Encrypted Channel T1078 Valid Accounts T1133 External Remote Services T1657 Financial Theft T1071 Application Layer Protocol T1070.004 File Deletion T1041 Exfiltration Over C2 Channel T1005 Data from Local System T1083 File and Directory Discovery T1574.011 Services Registry Permissions Weakness T1082 System Information Discovery T1112 Modify Registry T1033 System Owner/User Discovery T1087.002 Domain Account T1622 Debugger Evasion T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1543.003 Windows Service T1007 System Service Discovery T1202 Indirect Command Execution T1027.002 Software Packing T1485 Data Destruction T1140 Deobfuscate/Decode Files or Information T1499 Endpoint Denial of Service T1550.002 Pass the Hash T1490 Inhibit System Recovery T1656 Impersonation T1059.003 Windows Command Shell T1047 Windows Management Instrumentation T1105 Ingress Tool Transfer T1565.001 Stored Data Manipulation T1592.001 Hardware T1021 Remote Services T1021.001 Remote Desktop Protocol T1598.004 Spearphishing Voice T1059.004 Unix Shell T1568 Dynamic Resolution T1074 Data Staged T1018 Remote System Discovery T1496 Resource Hijacking T1562 Impair Defenses T1566 Phishing T1598 Phishing for Information T1020 Automated Exfiltration T1621 Multi-Factor Authentication Request Generation T1213 Data from Information Repositories T1199 Trusted Relationship T1491.001 Internal Defacement T1548.002 Bypass User Account Control T1571 Non-Standard Port T1016 System Network Configuration Discovery T1046 Network Service Discovery T1070.001 Clear Windows Event Logs T1055 Process Injection T1489 Service Stop T1021.002 SMB/Windows Admin Shares T1589.001 Credentials T1120 Peripheral Device Discovery T1036 Masquerading T1087 Account Discovery T1498 Network Denial of Service T1110 Brute Force T1069.002 Domain Groups T1567.002 Exfiltration to Cloud Storage T1134 Access Token Manipulation T1680 Local Storage Discovery T1570 Lateral Tool Transfer T1222.001 Windows File and Directory Permissions Modification T1561.001 Disk Content Wipe T1135 Network Share Discovery T1566.004 Spearphishing Voice T1190 Exploit Public-Facing Application T1053 Scheduled Task/Job T1059.001 Command and Scripting Interpreter: PowerShell T1072 Windows Management Instrumentation T1106 Native API T1569.002 System Services: Service Execution T1547 Server Software Component T1134.002 Access Token Manipulation: Create Process with Token T1497 Virtualization/Sandbox Evasion T1562.001 Impair Defenses: Disable or Modify Tools T1003.001 OS Credential Dumping: LSASS Memory T1552 Unsecured Credentials T1555 Credentials from Password Stores T1030 Data Transfer Size Limits T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

Reporting

Research mentioning BlackCat

Jul 16
Scworld

Nigeria faces rising cybercrime losses despite falling fraud incidents | brief | SC Media

Nigeria is strengthening its cybersecurity posture as cybercrime becomes more profitable even while reported fraud cases decline. Authorities are preparing a new national cybersecurity framework expected to mandate incident reporting, set minimum cybersecurity investment requirements, and expand public-private collaboration. The push comes as organizations in Nigeria faced an average of 4,361 attempted cyberattacks per week in June 2026, making the country one of Africa’s most targeted environments and often exposing victims to threat levels roughly double the global average. Financial losses have risen sharply, with digital-payment fraud reaching ₦25.85 billion in 2025, driven in part by insider-enabled schemes including SIM swap fraud, account compromise, and phishing. Nigeria already requires breach notification within 72 hours under its 2023 Data Protection Act, but enforcement and compliance remain uneven, especially among smaller organizations with limited training and security resources. Officials and industry observers say stronger enforcement, better reporting, and improved defenses against credential theft are critical to reducing cybercriminal profits in the country’s expanding digital economy.

Jul 15
Dark Reading

Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

Jul 25
Palo Alto Networks Unit 42

Muddled Libra Threat Assessment: Further-Reaching, Faster, More Impactful

Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption. Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.

Oct 19
Dfir

bedevil: Dynamic Linker Patching | dfir.ch

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.