BlackCat, also known as ALPHV and Noberus, is a Rust-based ransomware family operated as a ransomware-as-a-service (RaaS) program. Active from late 2021 until its apparent shutdown in March 2024, it was used by affiliates against organizations across the Americas, Europe, Asia, and Africa, including healthcare, government contractors, technology, logistics, and other enterprise sectors. BlackCat operations commonly used double extortion: affiliates stole victim data before encrypting systems and threatened publication through a leak site if payment was not made.
BlackCat has Windows, Linux, and VMware ESXi variants. Its configurable payloads can enumerate network and storage resources, use supplied credentials and remote-execution tooling for propagation, and target virtual machines and snapshots on ESXi hosts. Windows variants can bypass UAC through the CMSTPLUA COM interface, elevate token privileges, stop configured services and processes, delete volume shadow copies, and disable recovery features. The ransomware encrypts files using configurable AES or ChaCha20-based schemes and protects per-file encryption keys with an embedded RSA public key. It can append a configured extension, create ransom notes, and replace the desktop wallpaper with a ransom message.
BlackCat affiliates have used compromised remote-access credentials, including access obtained without multifactor authentication, to gain initial footholds, followed by privilege escalation and lateral movement. Affiliates have also deployed ExMatter, a separate data-exfiltration tool associated with BlackMatter and BlackCat operations, to identify and transfer selected files before ransomware deployment. BlackCat's configuration can be encrypted at runtime and may require an operator-supplied access token, hindering unauthorized execution and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
HTC Global Services has confirmed it suffered a cyber attack after the BlackCat ransomware group (also known as ALPHV) recently leaked photos of what it claimed to be data stolen from the IT services and business consulting company.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
In this incident, we identified the exploitation of CVE-2021-31207. This vulnerability abuses the New-MailboxExportRequest PowerShell command to export the user mailbox to an arbitrary file location, which could be used to write a web shell on the Exchange Server. | BlackCat (aka AlphaVM or AlphaV) is a ransomware family created in the Rust programming language and operated under a ransomware-as-a-service (RaaS) model.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–1709 is an Authentication Bypass Vulnerability in ConnectWise ScreenConnect instances caused by inadequate validation of URLs and insufficient access control, and it is a high severity vulnerability with confirmed real world exploitation by the BlackCat/Alphv ransomware gang and the Kimsuky group.
An analysis of ‘exp.exe’ indicated that it is a privilege escalation tool based on the exploitation of CVE-2022-24521 – a vulnerability in the Windows Common Log File System (CLFS) Driver, known to be used by several ransomware groups.
Afin de se latéraliser, les opérateurs du MOA ont tenté, sans succès, d’exploiter les vulnérabilités PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), puis ZeroLogon (CVE-2020-1472) via l’outil Mimikatz.
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
“Alphv (AKA BlackCat, Noberus) is a ransomware variant that has been active since at least November 2021 and operates using the double extortion method – where victim data is stolen and leaked if a ransom is not paid. Alphv operates as a RaaS…”
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for elf.blackcat ... description = "Detects elf.blackcat." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.blackcat"
BlackCat (a.k.a. ALPHV and Noberus) is a Ransomware-as-a-Service (RaaS) group that emerged in November 2021, making headlines for being a sophisticated ransomware written in Rust.
Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems.
It has also been linked to the ALPHV group (also known as BlackCat), though we believe that any similarities between Trigona and BlackCat ransomware are only circumstantial at best.
ALPHV (alias BlackCat et Noberus) est un RaaS actif depuis novembre 2021... l’ANSSI ne dispose pas de suffisamment d’éléments pour confirmer que FIN7 opère ALPHV.
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Processes spawned cmd.exe /c “wmic csproduct get UUID” ... cmd.exe /c “vssadmin.exe Delete Shadows /all /quiet” ... cmd.exe /c “arp -a”
A named pipe whose name contains the current process ID and random bytes generated above is created using CreateNamedPipeW
Privilege escalation via UAC bypass using CMSTPLUA COM interface ... BlackCat ransomware uses the auto-elevated CMSTPLUA interface {3E5FC7F9-9A51-4367-9063-A120244FBEC7} in order to escalate privileges
The process obtains a list of active services using EnumServicesStatusExW
The malicious process obtains the ARP table using the arp command, as shown below
There is a call to SHTestTokenMembership that verifies whether the user token is a member of the Administrators group
enable_network_discovery Switch to enable/disable network discovery bool
The executable takes a snapshot of all processes and threads in the system ... The processes are enumerated using the Process32FirstW and Process32NextW APIs
The malicious binary obtains information about the current system via a function call to GetSystemInfo
BlackCat traverses the file system using the FindFirstFileW and FindNextFileW APIs
All the tactics and techniques observed in this analysis can be mapped with the MITRE ATT&CK knowledge base as follows... T1087.002 Account Discovery: Domain Account Discovery
The file content is encrypted using the AES-128 algorithm ... The extension of the encrypted files is changed to uhwuvzu by the malware | The ransomware starts scanning the volumes on the local machine using FindFirstVolumeW ... All unmounted volumes are mounted via a function call to SetVolumeMountPointW
BlackCat stops the targeted service using the ControlService function | The ransomware terminates the targeted process by calling the TerminateProcess API
The ransomware deletes all volume shadow copies using the vssadmin.exe utility ... The binary disables Automatic Repair using the bcdedit tool | The ransomware deletes all volume shadow copies using the vssadmin.exe utility ... There is also a second process that is responsible for deleting all volume shadow copies with wmic
The Desktop wallpaper is changed to the above image by calling the SystemParametersInfoW API
DDoS. Own botnet for performing the most powerful DDoS attacks.
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlackCat/Alphv is mentioned only in passing as part of a comparison with other ransomware groups' rebranding and disruption.
Ransomware family referenced as an example of cybercrime infrastructure previously targeted by the FBI.
Ransomware used in the Change Healthcare attack; the group received a ransom payment but allegedly kept the money and failed to ensure deletion of the stolen data, enabling continued extortion.
Rust-based ransomware-as-a-service that encrypts enterprise data using AES-128-CTR and RSA-2048, or ChaCha20 when AES hardware support is unavailable; targets Windows, Linux, and VMware ESXi, deletes shadow copies/snapshots, uses double extortion, and can be deployed across victim networks via PowerShell and PsExec.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.