Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
BlackCat
BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation that emerged as one of the most prominent extortion threats of the early 2020s.
Profile source: Mallory opens in a new tabBlackCat
Family profile
BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation that emerged as one of the most prominent extortion threats of the early 2020s. The group provides file-encrypting malware and an extortion platform to affiliates, who conduct intrusions and share a portion of ransom proceeds with the core operators. BlackCat has been linked to more than 1,000 victims and hundreds of millions of dollars in ransom payments through late 2023.
BlackCat operations are characterized by double extortion: affiliates steal data from victim environments and then deploy ransomware to encrypt systems while threatening to leak stolen information if payment is not made. Reported affiliate activity includes breaching corporate networks, conducting post-compromise operations, exfiltrating data, and deploying the encryptor against organizations in the United States and other regions. Victims have included organizations in healthcare, financial services, retail, hospitality, nonprofit, and medical-device sectors, among others. The operation became particularly notorious for aggressive pressure tactics, including public leak-site extortion.
The service follows the standard ransomware affiliate model in which independent operators obtain access to victim networks and use BlackCat’s malware and negotiation infrastructure in exchange for a revenue share paid to the administrators. Public reporting and court records also show that BlackCat affiliates included insiders and cybersecurity professionals who abused trusted access to support extortion and ransomware deployment.
Law enforcement disrupted parts of the BlackCat infrastructure in December 2023, seized websites associated with the operation, and developed a decryption capability that helped victims recover systems without paying. Despite that disruption, BlackCat remained a major reference point in discussions of modern ransomware tradecraft and the risks posed by mature affiliate-driven extortion ecosystems.
Capabilities
- Exfiltration
- Extortion
- Lateral Movement
- Post Exploitation
Operational record
Reported operators
Threat actors
14 named in public reportingThe KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
The BlackCat (or ALPHV) ransomware came to prominence in late 2021 and is the first known ransomware to be written in the Rust programming language.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.
DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.
DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.
Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Exploited software
Vulnerabilities linked to BlackCat
17 CVEsMITRE ATT&CK
BlackCat in ATT&CK
89 distinct techniquesTechniques
89 techniquesReporting
Research mentioning BlackCat
Nigeria faces rising cybercrime losses despite falling fraud incidents | brief | SC Media
Nigeria is strengthening its cybersecurity posture as cybercrime becomes more profitable even while reported fraud cases decline. Authorities are preparing a new national cybersecurity framework expected to mandate incident reporting, set minimum cybersecurity investment requirements, and expand public-private collaboration. The push comes as organizations in Nigeria faced an average of 4,361 attempted cyberattacks per week in June 2026, making the country one of Africa’s most targeted environments and often exposing victims to threat levels roughly double the global average. Financial losses have risen sharply, with digital-payment fraud reaching ₦25.85 billion in 2025, driven in part by insider-enabled schemes including SIM swap fraud, account compromise, and phishing. Nigeria already requires breach notification within 72 hours under its 2023 Data Protection Act, but enforcement and compliance remain uneven, especially among smaller organizations with limited training and security resources. Officials and industry observers say stronger enforcement, better reporting, and improved defenses against credential theft are critical to reducing cybercriminal profits in the country’s expanding digital economy.
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
Muddled Libra Threat Assessment: Further-Reaching, Faster, More Impactful
Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption. Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.