ALPHV, also known as BlackCat and Noberus, is a prolific ransomware-as-a-service operation widely associated with Russian-speaking cybercrime. The group emerged in 2021 and became one of the most significant extortion actors globally before major law-enforcement disruption in late 2023. Its model relied on core operators providing ransomware, negotiation infrastructure, and leak-site support to affiliates, who conducted intrusions, stole data, encrypted systems, and shared a portion of proceeds with the administrators. ALPHV/BlackCat targeted a broad range of sectors, including healthcare, financial services, hospitality, retail, manufacturing, education, nonprofits, transportation, and other private-sector and critical-service organizations. Reporting has linked the operation to more than 1,000 victim organizations and hundreds of millions of dollars in ransom payments. The group was known for double-extortion tactics, combining data theft with encryption and threats to publish stolen information. It also demonstrated willingness to intensify pressure through public shaming and highly coercive leak-site activity. Operationally, ALPHV/BlackCat and its affiliates have been associated with exploitation of exposed remote access pathways and common enterprise weaknesses, including abuse of Remote Desktop Protocol for access and lateral movement. Reporting also links the ecosystem to the use of legitimate or dual-use tools such as AnyDesk, FileZilla, and network-scanning utilities during post-compromise activity, reflecting a broader pattern of blending commodity administration tools with ransomware tradecraft. The group has also been tied to exploitation activity following major vulnerabilities such as Log4Shell. The operation is notable for insider-enabled extortion cases involving cybersecurity professionals who secretly collaborated with the group while serving ransomware victims. In 2023, individuals including Angelo Martino, Kevin Martin, and Ryan Goldberg were convicted in the United States for providing confidential victim negotiation information to ALPHV/BlackCat and, in some cases, acting as affiliates to deploy the ransomware directly. Those cases showed the group’s willingness to exploit trusted intermediaries to maximize ransom demands. In December 2023, U.S. law enforcement disrupted portions of ALPHV/BlackCat infrastructure, seized websites, and developed a decryption capability that helped victims recover systems and avoid substantial ransom payments. Subsequent reporting indicates the operation later conducted an exit scam after receiving a large ransom, contributing to its decline as a coherent brand. Despite that disruption, ALPHV/BlackCat remains a highly significant reference point in ransomware history because of its scale, affiliate-driven model, aggressive extortion practices, and influence on later ransomware operations. Known aliases include ALPHV, BlackCat, Black Cat, and Noberus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware groups that exploited Log4Shell in incident response cases.
A ransomware operation that received insider negotiation intelligence from a DigitalMint negotiator and later had affiliates, including the conspirators, deploy BlackCat directly against additional victims for extortion payments.
Mentioned only in a related-articles link title; no substantive discussion in the content.
Ransomware group whose members received confidential victim negotiation data from a DigitalMint negotiator, used it to maximize ransom demands, and later partnered with insiders who helped attack organizations by breaching corporate networks, stealing data, and deploying ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.