← All ransomware groups

Ransomware group profile · #371 by claimed victims

BlackCat / ALPHV ransomwarealso ALPHV, Noberus

The first major ransomware family written in Rust, which gave it cross-platform reach including ESXi, and an affiliate-configurable encryptor unusual in its flexibility. Its affiliates included English-speaking social engineering crews, which changed the shape of the initial access stage considerably.

Defunct Russia First seen Nov 2021 ATT&CK G1068 ChaCha20 or AES per file, RSA wrapped; configurable per victim by the affiliate Russian
0Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
0Countries hit
0Leak-site URLs tracked
Latest claim recorded

Tactics, techniques and procedures

9 MITRE ATT&CK techniques mapped to BlackCat / ALPHV from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1078 Valid Accounts Valid credentials, frequently obtained by affiliates through social engineering of IT help desks rather than by technical means. Confirmed
Persistence T1219 Remote Access Tools AnyDesk, Splashtop, Atera and ngrok for durable access, chosen because they are ordinary IT tools. Confirmed
Credential Access T1003.001 LSASS Memory Credential dumping to expand access after the initial account. Confirmed
Credential Access T1621 Multi-Factor Authentication Request Generation MFA fatigue and help desk manipulation to defeat second factors, including persuading staff to enrol an attacker-controlled device. Confirmed
Discovery T1482 Domain Trust Discovery Domain trust and privilege path mapping before moving on the domain controller. Confirmed
Lateral Movement T1021.001 Remote Desktop Protocol RDP with harvested credentials, and remote access tooling where RDP was unavailable. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage ExMatter, a purpose-built exfiltration tool, alongside Rclone and MEGA. Confirmed
Impact T1486 Data Encrypted for Impact Rust encryptor with per-victim configuration, including a build targeting VMware ESXi that encrypts virtual machine storage directly and takes out many servers … Confirmed
Impact T1490 Inhibit System Recovery Shadow copies removed prior to encryption. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical BlackCat / ALPHV intrusion unfolds, section by section.

Social engineering

English-speaking affiliates targeting the help desk — Some affiliates specialised in calling the service desk, impersonating staff, and having credentials or MFA reset for them. It requires no malware and defeats most technical controls, and it is why help desk verification…

Encryption

Rust, and a hypervisor build — Writing in Rust gave portability and made analysis slower. The consequential part for defenders is the ESXi build: encrypting datastores directly takes out every guest at once, so hypervisor hardening does more good than…

Organisation

The exit scam and what it left behind — After a large payment in March 2024 the operators disappeared with affiliate funds. The resulting disputes played out publicly on RAMP, which is a searchable source of affiliate handles and grievances in this platform's …

Frequently asked

Is BlackCat / ALPHV ransomware still active?
BlackCat / ALPHV is tracked as defunct.
How many victims has BlackCat / ALPHV claimed?
VULONE has recorded 0 leak-site victim claims attributed to BlackCat / ALPHV, across 0 countries and 0 sectors.
Which industries does BlackCat / ALPHV target?
Sector data for BlackCat / ALPHV victims is not yet available.
Which countries are most affected by BlackCat / ALPHV?
Country data for BlackCat / ALPHV victims is not yet available.
Where does VULONE get BlackCat / ALPHV victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
VULONE primary-source researchVULONE1 Mar 2024
#StopRansomware: ALPHV Blackcat (AA23-353A)CISA / FBI19 Dec 2023

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].