Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
14 malware familiesExploits CVEs in the wild

BlackCat

Also known asalphvalphv_black_catAlphV/BlackCatblack_catblackcatblackcat_alphvembargonoberus

ALPHV/BlackCat is a financially motivated ransomware-as-a-service (RaaS) operation and prolific ransomware operator, also referred to in the provided content as ALPHV, BlackCat, Noberus, and Embargo. The group was among the most active ransomware actors in 2023, with one cited source listing 387 victims, and NCC Group tracking placed BlackCat among the top active ransomware groups in September 2023. The content also notes reduced activity after the late-2023 “ALPHV/BlackCat Ransomware Disruption.” The actor is associated with real-world exploitation of vulnerabilities, including confirmed exploitation of CVE-2024-1709 in ConnectWise ScreenConnect. The group has been linked to high-profile extortion activity including the Change Healthcare incident, where the content states Change Healthcare allegedly paid a $22 million ransom. The content also states that ALPHV filed a complaint with the U.S. Securities and Exchange Commission in November 2023 regarding MeridianLink’s breach disclosure. ALPHV/BlackCat operates through affiliates. The content states that Scattered Spider may have been connected to ALPHV/BlackCat as an initial access broker or affiliate, and that Octo Tempest became an affiliate in mid-2023. According to Microsoft reporting cited in the content, Octo Tempest initially used the ALPHV Collections leak site for extortion and by June 2023 began deploying ALPHV/BlackCat ransomware payloads against Windows and Linux, with recent focus on VMware ESXi. The content also notes LockBit attempted to recruit affiliates from ALPHV after disruption allegations. Tactics and techniques directly mentioned in the content include sophisticated defense evasion and fileless malware techniques, including reflective code loading; use of commercial remote management tools by affiliates; and cloud-focused ransomware activity. In 2023, Sophos X-Ops reported that BlackCat deployed ransomware against victim Azure Storage accounts using the Sphynx encryptor by downloading blobs in bulk, encrypting them, and reuploading them. The content also states that in April 2023 ALPHV used an updated version of the POORTRY tool in the compromise of NCR, contributing to an outage affecting its Aloha point-of-sale platform. The content further indicates ecosystem and tooling overlap with other ransomware operations. Malware hashes associated with 8Base infrastructure were also observed on onion sites associated with ALPHV, BianLian, Knight, and Play, suggesting shared backend or infrastructure relationships in the broader ransomware ecosystem. Separate reporting in the content mentions indirect relationships between a Cobalt Strike watermark and BlackCat, and associations of Infostealer.Eamfo with Noberus alongside Cuba and LockBit attacks. Aliases directly supported by the content: ALPHV, BlackCat, Noberus, and Embargo.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

64 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics84 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
4 techniques
T1078×6
Valid Accounts
T1133
External Remote Services
T1190×2
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.003
Spearphishing via Service
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1574
Hijack Execution Flow
TA0003
Persistence
8 techniques
T1037
Boot or Logon Initialization Scripts
T1037.001
Logon Script (Windows)
T1078×6
Valid Accounts
T1112
Modify Registry
T1133
External Remote Services
T1136
Create Account
T1505
Server Software Component
T1543
Create or Modify System Process
T1543.003×3
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
6 techniques
T1037
Boot or Logon Initialization Scripts
T1037.001
Logon Script (Windows)
T1055
Process Injection
T1068
Exploitation for Privilege Escalation
T1078×6
Valid Accounts
T1543
Create or Modify System Process
T1543.003×3
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
9 techniques
T1027×2
Obfuscated Files or Information
T1027.002
Software Packing
T1027.009
Embedded Payloads
T1036
Masquerading
T1055
Process Injection
T1070
Indicator Removal
T1070.004×2
File Deletion
T1078×6
Valid Accounts
T1140
Deobfuscate/Decode Files or Information
T1202
Indirect Command Execution
T1574
Hijack Execution Flow
T1620
Reflective Code Loading
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
4 techniques
T1003×2
OS Credential Dumping
T1003.001
LSASS Memory
T1003.002
Security Account Manager
T1110
Brute Force
T1557
Adversary-in-the-Middle
T1558
Steal or Forge Kerberos Tickets
T1558.003
Kerberoasting
TA0007
Discovery
7 techniques
T1007
System Service Discovery
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1046
Network Service Discovery
T1069
Permission Groups Discovery
T1069.002
Domain Groups
T1082
System Information Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
2 techniques
T1021×2
Remote Services
T1021.001
Remote Desktop Protocol
T1021.002
SMB/Windows Admin Shares
T1021.006
Windows Remote Management
T1550
Use Alternate Authentication Material
T1550.002
Pass the Hash
TA0009
Collection
4 techniques
T1114
Email Collection
T1213
Data from Information Repositories
T1557
Adversary-in-the-Middle
T1560
Archive Collected Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1105×2
Ingress Tool Transfer
TA0010
Exfiltration
3 techniques
T1041×3
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
T1567.003
Exfiltration to Text Storage Sites
TA0040
Impact
7 techniques
T1485
Data Destruction
T1486×20
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1498
Network Denial of Service
T1499×2
Endpoint Denial of Service
T1529
System Shutdown/Reboot
T1657
Financial Theft
IOCS

Observables

126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping64

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal14

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables126

Domains, IPs, and hashes tied to this actor, refreshed continuously.