Skip to content

BlackCat

BlackCat, also known as ALPHV and Noberus, is a Rust-based ransomware family operated through a ransomware-as-a-service model from approximately November 2021 until its apparent shutdown in March 2024.

Profile source: Mallory opens in a new tab

BlackCat

Family profile

BlackCat, also known as ALPHV and Noberus, is a Rust-based ransomware family operated through a ransomware-as-a-service model from approximately November 2021 until its apparent shutdown in March 2024. It supports double extortion: affiliates steal data before encrypting systems and threaten publication through a leak site if victims do not pay. BlackCat activity affected organizations across the Americas, Europe, Asia, and Africa, including healthcare, technology, government-adjacent, logistics, financial, IT, and manufacturing organizations.

The malware has Windows and Linux variants, including support for VMware ESXi environments. Its victim-specific runtime configuration can specify encryption behavior, ransomware notes, file and directory exclusions, service and process termination targets, compromised credentials, propagation settings, and ESXi virtual-machine and snapshot disruption. BlackCat encrypts files with symmetric cryptography and protects per-file keys with an embedded RSA public key. It can alter the desktop wallpaper with a ransom message.

BlackCat can enumerate hosts, volumes, network information, services, and running processes; terminate configured services and processes; delete shadow copies; disable recovery features; and attempt event-log clearing. It can elevate privileges through the CMSTPLUA COM interface and enable additional token privileges. Configurations may enable network discovery and self-propagation using embedded administrative tooling and compromised credentials. BlackCat affiliates have deployed the ExMatter data-exfiltration tool at scale, using legitimate remote-management access, compromised accounts, and administrative tooling for lateral movement. ExMatter identifies selected document, archive, database, and image files and transfers collected data to attacker-controlled infrastructure.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
4
Ransom notes
4
Leak sites
0 available

Reported operators

Threat actors

16 named in public reporting
Velvet Tempest

New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"

fin12

BlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.

Scattered Spider

Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems.

BlackCat

It has also been linked to the ALPHV group (also known as BlackCat), though we believe that any similarities between Trigona and BlackCat ransomware are only circumstantial at best.

FIN7

ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.

AdverCRow

The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.

Vanilla Tempest

Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.

Ambitious Scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

GOLD HARVEST

GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.

WIZARD SPIDER

DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.

Nitrogen

Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

ShadowSyndicate

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

FIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

Cicada3301

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

UNC4466

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

Exploited software

Vulnerabilities linked to BlackCat

18 CVEs

MITRE ATT&CK

BlackCat in ATT&CK

110 distinct techniques

Techniques

110 techniques
T1490 Inhibit System Recovery T1489 Service Stop T1486 Data Encrypted for Impact T1548.002 Bypass User Account Control T1120 Peripheral Device Discovery T1033 System Owner/User Discovery T1057 Process Discovery T1016 System Network Configuration Discovery T1570 Lateral Tool Transfer T1559.001 Component Object Model T1007 System Service Discovery T1491.001 Internal Defacement T1070.001 Clear Windows Event Logs T1083 File and Directory Discovery T1569.002 Service Execution T1559 Inter-Process Communication T1082 System Information Discovery T1059.003 Windows Command Shell T1135 Network Share Discovery T1068 Exploitation for Privilege Escalation T1112 Modify Registry T1021 Remote Services T1567.002 Exfiltration to Cloud Storage T1110 Brute Force T1657 Financial Theft T1498 Network Denial of Service T1222.001 Windows File and Directory Permissions Modification T1078 Valid Accounts T1087.002 Domain Account T1552.001 Credentials In Files T1587.001 Malware T1046 Network Service Discovery T1529 System Shutdown/Reboot T1070.004 File Deletion T1222 File and Directory Permissions Modification T1047 Windows Management Instrumentation T1133 External Remote Services T1484.001 Group Policy Modification T1566 Phishing T1036 Masquerading T1190 Exploit Public-Facing Application T1021.002 SMB/Windows Admin Shares T1189 Drive-by Compromise T1059.001 PowerShell T1048 Exfiltration Over Alternative Protocol T1566.001 Spearphishing Attachment T1583.008 Malvertising T1059 Command and Scripting Interpreter T1485 Data Destruction T1562 Impair Defenses T1053 Scheduled Task/Job T1021.004 SSH T1041 Exfiltration Over C2 Channel T1505.003 Web Shell T1074 Data Staged T1491 Defacement T1055 Process Injection T1059.004 Unix Shell T1543.003 Windows Service T1560.001 Archive via Utility T1578 Modify Cloud Compute Infrastructure T1003.001 LSASS Memory T1003 OS Credential Dumping T1560 Archive Collected Data T1497 Virtualization/Sandbox Evasion T1105 Ingress Tool Transfer T1012 Query Registry T1021.001 Remote Desktop Protocol T1071 Application Layer Protocol T1567 Exfiltration Over Web Service T1537 Transfer Data to Cloud Account T1573 Encrypted Channel T1005 Data from Local System T1574.011 Services Registry Permissions Weakness T1622 Debugger Evasion T1027 Obfuscated Files or Information T1202 Indirect Command Execution T1027.002 Software Packing T1140 Deobfuscate/Decode Files or Information T1499 Endpoint Denial of Service T1550.002 Pass the Hash T1656 Impersonation T1565.001 Stored Data Manipulation T1592.001 Hardware T1598.004 Spearphishing Voice T1568 Dynamic Resolution T1018 Remote System Discovery T1496 Resource Hijacking T1598 Phishing for Information T1020 Automated Exfiltration T1621 Multi-Factor Authentication Request Generation T1213 Data from Information Repositories T1199 Trusted Relationship T1571 Non-Standard Port T1589.001 Credentials T1087 Account Discovery T1069.002 Domain Groups T1134 Access Token Manipulation T1680 Local Storage Discovery T1561.001 Disk Content Wipe T1566.004 Spearphishing Voice T1072 Windows Management Instrumentation T1106 Native API T1547 Server Software Component T1134.002 Access Token Manipulation: Create Process with Token T1562.001 Impair Defenses: Disable or Modify Tools T1552 Unsecured Credentials T1555 Credentials from Password Stores T1030 Data Transfer Size Limits T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

Reporting

Research mentioning BlackCat

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Aug 12
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX

Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.