ALPHV, also known as BlackCat and tracked by some vendors as Ambitious Scorpius, was a prominent ransomware-as-a-service operation active through 2023 and early 2024. The group operated a leak site and relied on affiliates to conduct intrusions and extortion, making it one of the most prolific ransomware brands of its period. In March 2024, the operation was widely reported to have conducted an exit scam after law enforcement disruption, including selling its source code and falsely portraying its infrastructure as seized. ALPHV affiliates conducted enterprise intrusions that included Active Directory reconnaissance and broad internal discovery. Repeated use of ADRecon has been observed in intrusions associated with the group, indicating structured directory enumeration as part of its playbook. As a ransomware ecosystem actor, ALPHV used data theft and public leak pressure in addition to encryption, consistent with double-extortion operations and leak-site-based coercion. The operation functioned as a cybercriminal enterprise rather than a state-directed actor. Its activity was financially motivated and centered on extortion of victim organizations. BlackCat/ALPHV is the most widely recognized name for the actor, while Ambitious Scorpius is a vendor tracking alias for the same operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the group associated with the ALPHV ransomware-as-a-service program that Muddled Libra has partnered with.
Ransomware operators or affiliates associated with BlackCat/ALPHV that used ADRecon to enumerate Active Directory environments as part of intrusion activity.
Previously a leading ransomware group distributing ALPHV/BlackCat, Ambitious Scorpius ceased operations after law enforcement disruption, conducting an exit scam and selling its ransomware source code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.