Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 15 actorsExploits 16 CVEs

BlackCat

Also known asALPHVALPHV/BlackCatNoberus

BlackCat, also known as ALPHV and Noberus, is a ransomware family and ransomware-as-a-service (RaaS) operation that emerged in late 2021. It is widely noted as the first known ransomware written in Rust. The malware has both Windows and Linux variants, and reporting specifically notes deployments against VMware ESXi servers. BlackCat became one of the most prolific ransomware operations of 2023, with one cited count of 387 victims, and it has been linked in reporting to the 2023 MGM Resorts attack and the Change Healthcare incident.

BlackCat is operated through an affiliate model. Reported affiliates and associated clusters include Octo Tempest, also tracked as Scattered Spider/UNC3944 overlap, which became an ALPHV/BlackCat affiliate in mid-2023. Octo Tempest initially used the ALPHV leak site for data extortion and by June 2023 began deploying BlackCat ransomware payloads for both Windows and Linux, later focusing primarily on ESXi environments. Other reporting notes BlackCat payload use by Vice Society and by affiliates tracked as Ambitious Scorpius.

Observed behavior includes encryption of victim systems and double-extortion operations via leak-site pressure. BlackCat operators have required an execution password or command-line access token before encryption begins. On compromised hosts, BlackCat has been documented using net use commands to discover usernames and identify domain users. Affiliates associated with the operation have used ADRecon in multiple intrusions for Active Directory reconnaissance. Reporting also notes Azure-focused activity: in 2023, Sophos X-Ops reported that the BlackCat gang deployed the Sphynx encryptor against victim Azure Storage accounts by downloading blobs in bulk, encrypting them, and reuploading them to overwrite the originals; this method required only data-plane permissions such as a compromised storage account access key.

Initial access and exploitation associated with BlackCat activity include confirmed real-world exploitation of CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect, by the BlackCat/ALPHV ransomware gang. Reporting also references indirect linkage between a Cobalt Strike watermark (678358251) found in an intrusion and BlackCat and Black Basta.

Targeting reflected in the provided content spans multiple sectors, including gaming, hospitality, healthcare, manufacturing, retail, technology, financial services, managed service providers, law, natural resources, and consumer products. BlackCat has also been referenced in healthcare-sector intrusions and in cloud storage extortion scenarios. Known aliases in the content are ALPHV, ALPHV_BlackCat, BlackCat, and Noberus.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

16 CVES
CVE-2024-1709Authentication Bypass in ConnectWise ScreenConnect

CVE-2024–1709 is an Authentication Bypass Vulnerability in ConnectWise ScreenConnect instances caused by inadequate validation of URLs and insufficient access control, and it is a high severity vulnerability with confirmed real world exploitation by the BlackCat/Alphv ransomware gang and the Kimsuky group.

via medium s2wblogmedium.com
CVE-2022-24521Windows Common Log File System Driver Elevation of Privilege VulnerabilityExploited in the wild

An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.

via sygniasygnia.co
CVE-2021-34527PrintNightmareExploited in the wild

Afin de se latéraliser, les opérateurs du MOA ont tenté, sans succès, d’exploiter les vulnérabilités PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), puis ZeroLogon (CVE-2020-1472) via l’outil Mimikatz.

via cert ssicert.ssi.gouv.fr
CVE-2021-27878Arbitrary Command Execution via Flawed SHA Authentication in Veritas Backup Exec AgentExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-27876Arbitrary File Access via Flawed SHA Authentication in Veritas Backup Exec AgentExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-26858Microsoft Exchange Server post-auth arbitrary file write (ProxyLogon)Exploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-26857Microsoft Exchange Unified Messaging insecure deserialization RCEExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-34473ProxyShell pre-auth SSRF in Microsoft Exchange AutodiscoverExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-27065ProxyLogon post-auth arbitrary file write in Microsoft Exchange ServerExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-27877Authentication bypass in Veritas Backup Exec Agent via legacy SHA authenticationExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2018-13379Fortinet FortiOS SSL VPN Path TraversalExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2016-0099Secondary Logon Elevation of Privilege VulnerabilityExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange ServerExploited in the wild

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-34523Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell)

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2021-31207Post-auth Arbitrary File Write in Microsoft Exchange Server (ProxyShell)

“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”

via blackpoint cyberblackpointcyber.com
CVE-2024-37085VMware ESXi Active Directory Integration Authentication Bypass

Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...

via huntio blogblog.alphahunt.io
THREAT ACTORS

Groups observed using it

15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
AdverCRow

The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.

via medium s2wblogmedium.com
Scattered Spider

In mid-2023, Octo Tempest became an affiliate of ALPHV/BlackCat, a human-operated ransomware as a service (RaaS) operation. By June 2023, Octo Tempest started deploying ALPHV/BlackCat ransomware payloads (both Windows and Linux versions) to victims and lately has focused their deployments primarily on VMWare ESXi servers.

via microsoft generalmicrosoft.com
Vanilla Tempest

Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.

via acronisacronis.com
BlackCat

The BlackCat (or ALPHV) ransomware came to prominence in late 2021 and is the first known ransomware to be written in the Rust programming language.

via sentinelone labssentinelone.com
ambitious_scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
GOLD HARVEST

GOLD HARVEST has been known to operate as a ransomware affiliate, deploying ALPHV ransomware in attacks on MGM Resorts in 2023 and reportedly using RansomHub in attacks throughout 2024.

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

29 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (e.g., Cobalt Strike) or via exposed (and vulnerable) applications.

T1133External Remote ServicesEvidence1

The affiliate then gained access to the victim's network to steal data and deploy the ransomware to encrypt data and leave a ransom note.

Execution

3 techniques
T1047Windows Management InstrumentationEvidence1

The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'

T1059Command and Scripting InterpreterEvidence1

BlackCat also spawns a number of its own processes, with syntax (for Windows) as follows: WMIC.exe ... cmd.exe ... reg.exe ... vssadmin.exe ... arp -a

T1059.003Windows Command ShellEvidence1

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

Persistence

4 techniques
T1078Valid AccountsEvidence1

Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (e.g., Cobalt Strike) or via exposed (and vulnerable) applications.

T1112Modify RegistryEvidence1

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

T1133External Remote ServicesEvidence1

The affiliate then gained access to the victim's network to steal data and deploy the ransomware to encrypt data and leave a ransom note.

T1543.003Windows ServiceEvidence1

MITRE ATT&CK T1543.003 – Create or Modify System Process: Windows Service

Privilege Escalation

2 techniques
T1078Valid AccountsEvidence1

Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (e.g., Cobalt Strike) or via exposed (and vulnerable) applications.

T1543.003Windows ServiceEvidence1

MITRE ATT&CK T1543.003 – Create or Modify System Process: Windows Service

Stealth

7 techniques
T1027Obfuscated Files or InformationEvidence1

MITRE ATT&CK T1027 – Obfuscated Files or Information

T1027.002Software PackingEvidence1

MITRE ATT&CK T1027.002 – Obfuscated Files or Information: Software Packing

T1070.004File DeletionEvidence1

The ALPHV threat group is an early adopter of extortion schemes such as threatening victims with DDoS attacks, leaking exfiltrated data online...

T1078Valid AccountsEvidence1

Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (e.g., Cobalt Strike) or via exposed (and vulnerable) applications.

T1140Deobfuscate/Decode Files or InformationEvidence1

MITRE ATT&CK T1140 – Encode/Decode Files or Information

T1202Indirect Command ExecutionEvidence1

MITRE ATT&CK T1202 – Indirect Command Execution

T1622Debugger EvasionEvidence1

The LockBit 3.0 ransomware uses a variety of anti-analysis techniques to hinder static and dynamic analysis... Several techniques are implemented for detecting the presence of a debugger and hindering dynamic analysis.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

Discovery

6 techniques
T1007System Service DiscoveryEvidence1

MITRE ATT&CK T1007 – System Service Discovery

T1033System Owner/User DiscoveryEvidence1

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.

T1082System Information DiscoveryEvidence2

Immediately upon launch, the malware will attempt to validate the existence of the previously mentioned access-token, followed by querying for the system UUID (wmic).

T1083File and Directory DiscoveryEvidence1

The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").

T1087.002Domain AccountEvidence1

AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.

T1622Debugger EvasionEvidence1

The LockBit 3.0 ransomware uses a variety of anti-analysis techniques to hinder static and dynamic analysis... Several techniques are implemented for detecting the presence of a debugger and hindering dynamic analysis.

Lateral Movement

1 technique
T1550.002Pass the HashEvidence1

MITRE ATT&CK T1550.002 – Use Alternate Authentication Material: Pass the Hash

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

Most recently, IcedID has reportedly been used to download and execute Quantum Locker ransomware... Emotet is being used to load Quantum and ALPHV ransomware... and is being used to load and execute IcedID.

Exfiltration

3 techniques
T1041Exfiltration Over C2 ChannelEvidence1

The current version of Qyick does not have data exfiltration capabilities. However, lucrostm has announced that future versions will feature execution of arbitrary executable code, meant primarily for the execution of data exfiltration capabilities.

T1537Transfer Data to Cloud AccountEvidence1

The affiliate then gained access to the victim's network to steal data and deploy the ransomware to encrypt data and leave a ransom note.

T1567Exfiltration Over Web ServiceEvidence1

The victim was directed to the ALPHV BlackCat panel hosted on the dark web where the victim could communicate with the ransomware group to negotiate the ransom.

Impact

5 techniques
T1485Data DestructionEvidence1

-- no -vm-snapshot-kill Do not wipe VMs snapshots on ESXi

T1486Data Encrypted for ImpactEvidence18

By June 2023, Octo Tempest started deploying ALPHV/BlackCat ransomware payloads... This activity targets both Windows and Unix/Linux endpoints and VMware hypervisors using a variant of ALPHV/BlackCat.

T1490Inhibit System RecoveryEvidence3

BlackCat attempts to delete VSS (Volume Shadow Copies)... cmd.exe (vssadmin.exe) /c "vssadmin.exe delete shadows /all /quiet" ... wmic.exe Shadowcopy Delete ... bcdedit.exe /set {default} recoveryenabled No

T1499Endpoint Denial of ServiceEvidence2

The ALPHV threat group is an early adopter of extortion schemes such as threatening victims with DDoS attacks...

T1657Financial TheftEvidence1

In one instance, the three men extorted a victim for roughly $1.2 million in Bitcoin and then split the proceeds. | Starting in April of that year, while working as a negotiator on behalf of five ransomware victims, Martino shared confidential information with BlackCat attackers about his clients’ positions and strategies to help maximize their ransom payments. That information included details such as victims’ insurance policy limits and other internal negotiation positions.

Other

1 technique
T1656ImpersonationEvidence1

A Muddled Libra-style social-engineering campaign against a major host-city hotel operator collapses room access, mobile check-in and PoS for 48-72 hours

INDICATORS OF COMPROMISE

IOCs tracked for this family

248 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
75 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
173 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 days ago
hash.sha256●●●●●●●●●●●●View more in app4 days ago
hash.sha256●●●●●●●●●●●●View more in app4 days ago
domain●●●●●●●●●●●●View more in app10 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app22 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching248

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution15

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities16

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping29

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.