Ambitious Scorpius, also known as BlackCat and ALPHV, is a financially motivated cybercriminal operation responsible for the ALPHV/BlackCat ransomware-as-a-service program. It distributes ransomware through affiliates and operates a victim leak site to support extortion. BlackCat affiliates have repeatedly used ADRecon, a PowerShell-based tool that queries LDAP to collect Active Directory information and produce network inventory reports, during intrusions. The operation was the second-most prolific ransomware group by victim leak-site postings in 2023. An FBI disruption in December 2023 reduced its activity. In March 2024, its operators conducted an exit scam involving the sale of ALPHV/BlackCat source code and a fabricated claim that the FBI had seized their site and infrastructure. Muddled Libra, also known as Scattered Spider and UNC3944, has been associated with the ALPHV affiliate ecosystem but is a distinct threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the group associated with the ALPHV ransomware-as-a-service program that Muddled Libra has partnered with.
Ransomware operators or affiliates associated with BlackCat/ALPHV that used ADRecon to enumerate Active Directory environments as part of intrusion activity.
Referenced as the actor associated with a previously reported ransomware attack whose infrastructure overlapped with the current investigation. The article states that the group ceased operations following an exit scam and cautions that the overlap could instead reflect an affiliate or shared cybercrime cluster; it does not attribute the payment-data theft to Ambitious Scorpius.
Previously a leading ransomware group distributing ALPHV/BlackCat, Ambitious Scorpius ceased operations after law enforcement disruption, conducting an exit scam and selling its ransomware source code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.