New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
BlackCat
BlackCat, also known as ALPHV and Noberus, is a Rust-based ransomware family operated through a ransomware-as-a-service model from approximately November 2021 until its apparent shutdown in March 2024.
Profile source: Mallory opens in a new tabBlackCat
Family profile
BlackCat, also known as ALPHV and Noberus, is a Rust-based ransomware family operated through a ransomware-as-a-service model from approximately November 2021 until its apparent shutdown in March 2024. It supports double extortion: affiliates steal data before encrypting systems and threaten publication through a leak site if victims do not pay. BlackCat activity affected organizations across the Americas, Europe, Asia, and Africa, including healthcare, technology, government-adjacent, logistics, financial, IT, and manufacturing organizations.
The malware has Windows and Linux variants, including support for VMware ESXi environments. Its victim-specific runtime configuration can specify encryption behavior, ransomware notes, file and directory exclusions, service and process termination targets, compromised credentials, propagation settings, and ESXi virtual-machine and snapshot disruption. BlackCat encrypts files with symmetric cryptography and protects per-file keys with an embedded RSA public key. It can alter the desktop wallpaper with a ransom message.
BlackCat can enumerate hosts, volumes, network information, services, and running processes; terminate configured services and processes; delete shadow copies; disable recovery features; and attempt event-log clearing. It can elevate privileges through the CMSTPLUA COM interface and enable additional token privileges. Configurations may enable network discovery and self-propagation using embedded administrative tooling and compromised credentials. BlackCat affiliates have deployed the ExMatter data-exfiltration tool at scale, using legitimate remote-management access, compromised accounts, and administrative tooling for lateral movement. ExMatter identifies selected document, archive, database, and image files and transfers collected data to attacker-controlled infrastructure.
Capabilities
- Defense Evasion
- Exfiltration
- Lateral Movement
- Privilege Escalation
- Reconnaissance
- Scanning
Operational record
Reported operators
Threat actors
16 named in public reportingBlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.
Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems.
It has also been linked to the ALPHV group (also known as BlackCat), though we believe that any similarities between Trigona and BlackCat ransomware are only circumstantial at best.
ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.
DEV-0504 was responsible for deploying BlackCat ransomware in companies in the energy sector in January 2022.
Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Exploited software
Vulnerabilities linked to BlackCat
18 CVEsMITRE ATT&CK
BlackCat in ATT&CK
110 distinct techniquesTechniques
110 techniquesReporting
Research mentioning BlackCat
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Ransomware Group clop Hits: 9ALTITUDES.COM
Ransomware Group clop Hits: WATERLANDPE.COM
Ransomware Group clop Hits: NETPOWER.COM
Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)
Ransomware Group clop Hits: IRCO.COM
Ransomware Group clop Hits: LARGAN.COM.TW
Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX
Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.