Ransomware group profile · #371 by claimed victims
BlackCat / ALPHV ransomwarealso ALPHV, Noberus
The first major ransomware family written in Rust, which gave it cross-platform reach including ESXi, and an affiliate-configurable encryptor unusual in its flexibility. Its affiliates included English-speaking social engineering crews, which changed the shape of the initial access stage considerably.
Tactics, techniques and procedures
9 MITRE ATT&CK techniques mapped to BlackCat / ALPHV from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1078 Valid Accounts | Valid credentials, frequently obtained by affiliates through social engineering of IT help desks rather than by technical means. | Confirmed |
| Persistence | T1219 Remote Access Tools | AnyDesk, Splashtop, Atera and ngrok for durable access, chosen because they are ordinary IT tools. | Confirmed |
| Credential Access | T1003.001 LSASS Memory | Credential dumping to expand access after the initial account. | Confirmed |
| Credential Access | T1621 Multi-Factor Authentication Request Generation | MFA fatigue and help desk manipulation to defeat second factors, including persuading staff to enrol an attacker-controlled device. | Confirmed |
| Discovery | T1482 Domain Trust Discovery | Domain trust and privilege path mapping before moving on the domain controller. | Confirmed |
| Lateral Movement | T1021.001 Remote Desktop Protocol | RDP with harvested credentials, and remote access tooling where RDP was unavailable. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | ExMatter, a purpose-built exfiltration tool, alongside Rclone and MEGA. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | Rust encryptor with per-victim configuration, including a build targeting VMware ESXi that encrypts virtual machine storage directly and takes out many servers … | Confirmed |
| Impact | T1490 Inhibit System Recovery | Shadow copies removed prior to encryption. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical BlackCat / ALPHV intrusion unfolds, section by section.
Social engineering
English-speaking affiliates targeting the help desk — Some affiliates specialised in calling the service desk, impersonating staff, and having credentials or MFA reset for them. It requires no malware and defeats most technical controls, and it is why help desk verification…
Encryption
Rust, and a hypervisor build — Writing in Rust gave portability and made analysis slower. The consequential part for defenders is the ESXi build: encrypting datastores directly takes out every guest at once, so hypervisor hardening does more good than…
Organisation
The exit scam and what it left behind — After a large payment in March 2024 the operators disappeared with affiliate funds. The resulting disputes played out publicly on RAMP, which is a searchable source of affiliate handles and grievances in this platform's …
Frequently asked
Is BlackCat / ALPHV ransomware still active?
How many victims has BlackCat / ALPHV claimed?
Which industries does BlackCat / ALPHV target?
Which countries are most affected by BlackCat / ALPHV?
Where does VULONE get BlackCat / ALPHV victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| VULONE primary-source research | VULONE | 1 Mar 2024 |
| #StopRansomware: ALPHV Blackcat (AA23-353A) | CISA / FBI | 19 Dec 2023 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].