ALPHV, also known as AlphaV and widely associated with the BlackCat ransomware operation, is a financially motivated ransomware threat actor known for double-extortion activity in which victim data is stolen and threatened with public release in addition to file encryption. The group has been publicly linked to high-profile attacks, including against healthcare-sector victims, and has used data-leak pressure as a core coercive mechanism. ALPHV has also demonstrated more aggressive extortion behavior beyond standard leak threats, including contacting regulators to increase pressure on victims, a tactic consistent with triple-extortion-style operations. The actor has targeted organizations for financial gain and has been associated with large ransom demands and negotiations. Reported victimology in the supplied facts includes healthcare organizations and publicly traded companies. ALPHV’s operations fit the broader modern ransomware model in which exfiltration is central to extortion credibility, and public disclosure threats are used to compel payment even when restoration from backups is possible. Law-enforcement action significantly disrupted ALPHV in late 2023 through a multinational operation involving the U.S. Department of Justice, Germany, Denmark, and Europol. The FBI developed a decryption capability that assisted hundreds of victims and reduced ransom payments. Despite disruption, ALPHV remains notable for its role in the evolution of extortion-centric ransomware tradecraft and for using public and regulatory pressure to amplify victim impact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware/extortion group that allegedly received a payment from Optum to prevent disclosure of stolen health data.
Employs multi-extortion tactics, including reporting victims to regulatory authorities to increase pressure for ransom payment.
Ransomware group disrupted by US/international law enforcement; victims were assisted via a decryption tool to reduce ransom payments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.