BlackCat, also known as ALPHV and Noberus, is a ransomware family distributed through a financially motivated ransomware-as-a-service operation. Its payloads target Windows, Linux, and VMware ESXi environments, enabling affiliates to disrupt enterprise systems and virtualized infrastructure. The operation combines encryption with threats to disclose stolen information to extort victims. Its affiliate program advertised revenue shares of up to 90% of ransom proceeds.
BlackCat can replicate across connected servers using PsExec, supporting lateral distribution within compromised networks. Payload execution can require a key, hindering analysis. Affiliate intrusion methods vary; documented activity includes targeting publicly exposed Veritas Backup Exec installations affected by CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878. Legitimate remote-access tools, including AnyDesk and ScreenConnect, have also appeared in attack chains preceding BlackCat deployment.
Associated affiliates include Scattered Spider, which became involved in the operation in mid-2023, Pistachio Tempest, also tracked as DEV-0237 and FIN12, and ShadowSyndicate. BlackCat attacks have affected healthcare organizations, notably Change Healthcare, whose compromise disrupted healthcare payment and prescription-processing services. The operation was subject to law enforcement disruption in late 2023, and former affiliates subsequently joined other ransomware programs, including RansomHub.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
The vulnerabilities, identified as CVE-2021-27876, CVE-2021-27877 and CVE-2021-27878, existed due to a flaw in the SHA authentication scheme used by Backup Exec.
At-Bay’s Cyber Research team confirmed that BlackCat (aka Alphv) successfully exploited the GoAnywhere MFT vulnerability (CVE-2023-0669) against a U.S. business in February 2023. Clop had previously exploited the same vulnerability and claimed to have compromised over 100 organizations. | At-Bay’s Cyber Research team confirmed that BlackCat has successfully exploited the GoAnywhere MFT vulnerability and attacked a U.S. business in February 2023.
HTC Global Services has confirmed it suffered a cyber attack after the BlackCat ransomware group (also known as ALPHV) recently leaked photos of what it claimed to be data stolen from the IT services and business consulting company.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
In this incident, we identified the exploitation of CVE-2021-31207. This vulnerability abuses the New-MailboxExportRequest PowerShell command to export the user mailbox to an arbitrary file location, which could be used to write a web shell on the Exchange Server. | BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–1709 is an Authentication Bypass Vulnerability in ConnectWise ScreenConnect instances caused by inadequate validation of URLs and insufficient access control, and it is a high severity vulnerability with confirmed real world exploitation by the BlackCat/Alphv ransomware gang and the Kimsuky group.
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
Afin de se latéraliser, les opérateurs du MOA ont tenté, sans succès, d’exploiter les vulnérabilités PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), puis ZeroLogon (CVE-2020-1472) via l’outil Mimikatz.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This latest attack follows a $22 million ransom payment made by Change Healthcare to the BlackCat group, aimed at preventing a data leak and restoring their systems.
One of the Cobalt Strike C2 IP addresses identified in this activity matches an IP address mentioned in a Sophos X-Ops report, where a similar infection chain resulted in an Ambitious Scorpius (BlackCat) ransomware attack.
In mid-2023, it was reported that Scattered Spider became involved in the BlackCat ransomware operation, initiating the deployment of ransomware payloads on both Windows and Linux systems, and subsequently targeting VMWare ESXi servers.
The operators have also reportedly recruited several former ALPHV affiliates, including an individual known as Notchy.
Pistachio Tempest (DEV-0237/FIN12), an affiliate known to use Conti and BlackCat, experimented with Agenda ransomware in June 2022.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Scattered Spider obtained initial access before one of the aforementioned groups was observed using ransomware for encryption.”
The ransomware deletes all volume shadow copies using the vssadmin.exe utility ... The binary disables Automatic Repair using the bcdedit tool | The ransomware deletes all volume shadow copies using the vssadmin.exe utility ... There is also a second process that is responsible for deleting all volume shadow copies with wmic
295 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Appears only in background discussion of ransomware affiliates moving to Qilin.
Ransomware accounting for 16% of successful attacks investigated by Coveware in the second quarter of 2023. The article also reports that Royal borrowed its loader.
Mentioned only as the ransomware operation whose former affiliates were reportedly recruited by RansomHub. The content does not describe ALPHV's technical behavior or its deployment in these attacks.
Ransomware mentioned as background context for prior attacks involving SimpleHelp. No ransomware-specific behavior or distribution details are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.