ALPHV/BlackCat, also known as BlackCat and Noberus, is a financially motivated, Russian cybercriminal ransomware-as-a-service operation that emerged in late 2021. Its operators developed ransomware and maintained extortion infrastructure, while affiliates compromised organizations, stole data, and deployed encryption payloads. The program recruited experienced intrusion specialists and initial access brokers through Russian-language cybercrime forums and advertised affiliate payments of up to 90% of ransom proceeds. Affiliates included Scattered Spider and Pistachio Tempest, also known as FIN12 and DEV-0237; these are distinct threat actors rather than aliases for the core operation. BlackCat uses Rust-based ransomware targeting Windows, Linux, and VMware ESXi environments. Its operations employ double extortion, combining encryption with threats to publish stolen information through data-leak infrastructure. Observed intrusion methods include compromised credentials and exploitation of publicly exposed software, including Veritas Backup Exec. Attackers conduct reconnaissance, compromise Active Directory accounts, exfiltrate sensitive information, and use PowerShell, Cobalt Strike, administrative utilities, scheduled tasks, and malicious Group Policy Objects to deploy ransomware. They disable security defenses and preserve access during intrusions. In February 2024, ALPHV/BlackCat attacked Change Healthcare using stolen credentials against an exposed remote-access service without multifactor authentication, causing extensive disruption to US healthcare payment and claims processing. Change Healthcare paid approximately $22 million, but the payment did not prevent subsequent extortion involving the stolen data. Law enforcement disrupted BlackCat infrastructure, and the operators subsequently conducted an exit scam in 2024, leaving affiliates to migrate to other ransomware programs. The FBI linked BlackCat developers and money launderers to DarkSide and BlackMatter, but those personnel connections do not establish that the operations were identical.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
2 more CVEs tied to this actor tracked in Mallory.
135 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an operation whose affiliates subsequently joined Qilin; no specific ALPHV activity is described.
Mentioned as a historical example of an intermediary breach causing widespread downstream disruption. ALPHV breached a healthcare-payments intermediary, disrupting U.S. pharmacy and insurance operations. No attribution to ALPHV is made for the EY breach.
Mentioned solely as a comparison with XuanyeGroup’s public Telegram-based approach. The article describes its use of Tor-based leak sites and private negotiation portals, without linking it to the ASOS incident.
A ransomware group described as maintaining a close working relationship with Royal, which continued borrowing its loader. Its namesake ransomware also appeared in the article's comparison of successful ransomware incidents investigated by Coveware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.