BlackCat, also known as ALPHV and Noberus, is a ransomware-as-a-service operation and ransomware family that emerged in late 2021. It is widely recognized as one of the first major professional ransomware families implemented in Rust, with cross-platform variants for Windows, Linux, and VMware ESXi environments. Reporting has frequently linked it to personnel, tradecraft, or lineage associated with the DarkSide and BlackMatter ecosystems, although direct continuity has not always been conclusively established.
BlackCat is a double-extortion ransomware that steals data before encrypting systems and threatens public release through a leak site if victims do not pay. Multiple reports also describe triple-extortion features or services associated with the operation, including the threat of distributed denial-of-service pressure and phone-based coercion. The malware is highly configurable, with options governing file-encryption behavior, ransom-note content, process and service termination, exclusion lists, network discovery, self-propagation, wallpaper changes, and ESXi-specific actions such as virtual machine termination and snapshot deletion.
The ransomware has been observed using legitimate administrative tooling and post-compromise tradecraft to maximize impact in enterprise environments. Documented behaviors include privilege escalation through User Account Control bypass, lateral movement and propagation with PsExec and compromised credentials, service and process termination, deletion of shadow copies, disabling of recovery mechanisms, and attempted clearing of event logs. BlackCat samples and related tooling have also been associated with embedded or companion capabilities for data exfiltration prior to encryption.
BlackCat has targeted organizations across multiple regions and sectors, including healthcare, manufacturing, information technology, logistics, finance, and government-related environments. Healthcare has been a particularly notable target for extortion involving threatened publication of patient data. The operation has also been associated with attacks affecting Microsoft Exchange environments and campaigns against virtualized infrastructure, especially ESXi hosts.
Initial access associated with BlackCat affiliates has included exploitation of exposed vulnerabilities, use of valid accounts, and malvertising-driven delivery chains. Reported intrusion paths include exploitation of Microsoft Exchange vulnerabilities, compromise of remote access through stolen credentials, and malvertising campaigns that impersonated business software to deliver initial-access malware later used in BlackCat intrusions. The operation has functioned through an affiliate model, and public reporting has tied different affiliates and partner ecosystems to its campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
In this incident, we identified the exploitation of CVE-2021-31207. This vulnerability abuses the New-MailboxExportRequest PowerShell command to export the user mailbox to an arbitrary file location, which could be used to write a web shell on the Exchange Server. | BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–1709 is an Authentication Bypass Vulnerability in ConnectWise ScreenConnect instances caused by inadequate validation of URLs and insufficient access control, and it is a high severity vulnerability with confirmed real world exploitation by the BlackCat/Alphv ransomware gang and the Kimsuky group.
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
Afin de se latéraliser, les opérateurs du MOA ont tenté, sans succès, d’exploiter les vulnérabilités PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), puis ZeroLogon (CVE-2020-1472) via l’outil Mimikatz.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
BlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.
Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems.
It has also been linked to the ALPHV group (also known as BlackCat), though we believe that any similarities between Trigona and BlackCat ransomware are only circumstantial at best.
ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
credentials Array of compromised credentials for escalation and propagation [][]string
Может распространяться путём взлома через незащищенную конфигурацию RDP
credentials Array of compromised credentials for escalation and propagation [][]string
On the day of the attack, the attacker logged in to the domain controller and opened the group policy management interface. The attackers then dropped and executed a file named 'apply.ps1.' We believe this script created and prepared the group policy to cause the execution of the ransomware throughout the domain.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
File permissions were changed using icacls.exe, a command-line utility that can be used to modify NTFS permissions, as well as net share commands.
All the tactics and techniques observed in this analysis can be mapped with the MITRE ATT&CK knowledge base as follows... T1222.001 File and Directory Permissions Modification: Windows File and Directory Permissions Modification
On the day of the attack, the attacker logged in to the domain controller and opened the group policy management interface. The attackers then dropped and executed a file named 'apply.ps1.' We believe this script created and prepared the group policy to cause the execution of the ransomware throughout the domain.
enable_network_discovery Switch to enable/disable network discovery bool
Query the system UUID using wmic. The universally unique identifier (UUID) is later used, together with the token, to identify the victim in a Tor website hosted by the malicious actors.
only certain affiliates have access to a Linux variant of the Conti ransomware, targeting ESXi systems | they try to encrypt as many systems as possible
kill_services List of services to be terminated []string | kill_processes List of processes to be terminated []string
enable_esxi_vm_snapshot_kill Switch to enable/disable Snapshot deletion on ESXi Hosts bool
If enabled in the configuration, the ransomware also changes the user’s wallpaper with the following message.
DDoS. Own botnet for performing the most powerful DDoS attacks.
269 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlackCat/Alphv is mentioned only in passing as part of a comparison with other ransomware groups' rebranding and disruption.
Ransomware family referenced as an example of cybercrime infrastructure previously targeted by the FBI.
Ransomware used in the Change Healthcare attack; the group received a ransom payment but allegedly kept the money and failed to ensure deletion of the stolen data, enabling continued extortion.
Rust-based ransomware-as-a-service that encrypts enterprise data using AES-128-CTR and RSA-2048, or ChaCha20 when AES hardware support is unavailable; targets Windows, Linux, and VMware ESXi, deletes shadow copies/snapshots, uses double extortion, and can be deployed across victim networks via PowerShell and PsExec.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.