Cisco Talos reported that BlackCat (also tracked as ALPHV) shares infrastructure, tools, filenames, and intrusion tradecraft with the BlackMatter/DarkSide ransomware ecosystem, indicating with moderate confidence that at least one BlackMatter affiliate became an early BlackCat operator rather than the group being a simple rebrand. In side-by-side intrusions, Talos observed similar human-operated attack phases including persistent access through tunneling tools, credential theft via LSASS dumping, lateral movement with Impacket wmiexec, WinRM/PowerShell, and RDP, and domain-wide ransomware deployment from the domain controller’s NETLOGON share after scripts such as apply.ps1, defender.vbs, and def.vbs were staged. Talos said BlackCat dwell time exceeded 15 days in one case and noted that more than 30 percent of observed compromises affected U.S.-based organizations.
Other reporting and technical analyses describe BlackCat as a Rust-based ransomware-as-a-service platform that emerged in late 2021, recruited affiliates from groups including REvil, BlackMatter, and DarkSide, and offered operators roughly 80 to 90 percent of ransom proceeds. Researchers said the malware targets Windows, Linux, and VMware ESXi environments, uses double extortion with Tor-based payment portals, and includes capabilities such as CMSTPLUA privilege escalation, shadow-copy deletion, service and process termination, and configurable encryption using embedded keys. The overlap with DarkSide-era techniques is reinforced by prior DarkSide analyses showing similar affiliate-driven operations, extortion infrastructure, and malware behaviors, supporting the view that BlackCat grew out of the same criminal talent pool rather than appearing as an entirely separate threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
26 events from the most recent confirmed update back to the earliest known activity.
A federal indictment was filed in the Southern District of Florida charging Kevin Tyler Martin, Ryan Clifford Goldberg, and an unnamed co-conspirator with extortion conspiracy, extortion, and intentional damage to protected computers. The indictment alleges the conspiracy ran from May 2023 to April 2025 and targeted at least five organizations while the defendants held trusted cybersecurity roles.
Ryan Clifford Goldberg participated in a consensual recorded FBI interview and allegedly admitted he had been recruited to ransom companies and that the group used ALPHV/BlackCat ransomware. He also allegedly said proceeds were routed through a cryptocurrency mixing service and multiple wallets.
After the FBI raided the unnamed co-conspirator's home, Martin allegedly contacted Goldberg and panicked about the raid, according to the indictment. The raid marked a significant law-enforcement step in the alleged BlackCat affiliate case.
The indictment alleges the conspirators attacked a Virginia drone manufacturer in November 2023 and sought approximately $300,000. Prosecutors said the group used BlackCat ransomware and double-extortion tactics in the campaign.
The indictment alleges the conspirators attacked a California engineering firm in October 2023 and attempted to extort about $1 million. The attack was part of the same alleged ALPHV/BlackCat affiliate conspiracy.
A later BlackCat 2.0 variant called Sphynx was reported in August 2023. The profile said this version included tools such as Impacket and RemCom for propagation inside compromised networks.
The indictment alleges the conspirators attacked a California doctor's office in July 2023 and sought approximately $5 million. The case describes the operation as using double-extortion tactics involving both encryption and threats to publish stolen data.
A Tampa medical device manufacturer was allegedly attacked and its servers encrypted by the conspirators, who demanded about $10 million. The victim later paid approximately $1.27 million in cryptocurrency, according to the indictment.
A Maryland pharmaceutical company was allegedly attacked in May 2023 through server encryption and data theft by the same BlackCat affiliate conspiracy. Forensic analysis cited in the indictment showed Goldberg searched for the victim's name on or about May 4, 2023, shortly before the attack.
According to a later U.S. indictment, an unnamed co-conspirator obtained an affiliate account on the ALPHV/BlackCat panel and shared access with Kevin Tyler Martin and Ryan Clifford Goldberg. Prosecutors allege the trio then used BlackCat infrastructure to conduct ransomware attacks and split proceeds with BlackCat administrators.
Cisco Talos published analysis concluding with moderate confidence that at least one BlackMatter affiliate was an early adopter of BlackCat. The report cited overlapping command-and-control infrastructure, shared tools and filenames, and similar intrusion sequences between September 2021 and December 2021 incidents.
A BlackCat representative told Recorded Future that BlackCat had a connection to BlackMatter but was not a direct rebranding of it. The representative said BlackCat included affiliates from other ransomware-as-a-service groups and had taken knowledge from other outfits.
KrebsOnSecurity reported clues suggesting a developer using the handle Binrs may have helped code ALPHV/BlackCat, tying the persona to multiple Russian-language forums, a shared ToX ID, the Telegram handle @CookieDays, and the DuckerMan alias. The report also noted ALPHV was recruiting operators from REvil, BlackMatter, and DarkSide and offering affiliates up to 90% of ransom payments.
Symantec published technical analysis of the new Rust-based BlackCat ransomware, also referred to as Noberus. The report contributed early public technical detail on the malware family.
S2W reported similarities between configuration fields used by BlackCat and BlackMatter. The research highlighted that BlackCat was written in Rust while DarkSide and BlackMatter were written in C/C++.
BlackCat was advertised from early December 2021 on the Russian-language XSS and Exploit forums. The operators recruited pentesters, operators, and participants from other ransomware projects while promising affiliates 80% to 90% of ransom proceeds.
Multiple researchers publicly identified the ALPHV/BlackCat operation in December 2021. MalwareHunter Team discussed the group, and other reporting described it as a newly discovered Rust-based ransomware-as-a-service strain.
A December 2021 BlackCat intrusion used a domain and IP infrastructure that Talos said had also been used in a BlackMatter deployment three months earlier. Talos found similar attack phases, persistence, credential dumping, and domain-wide ransomware execution behavior across the two incidents.
In late November 2021, ALPHV/BlackCat attacked Oiltanking GmbH, affecting 13 fuel terminals and disrupting more than 200 petrol stations in northern Germany. The incident was cited as an early notable BlackCat victim case.
Technical profiling stated that BlackCat activity was first observed in mid-to-late November 2021, with an earlier variant created in early November. The malware targeted enterprise environments across Windows, Linux, and VMware ESXi systems.
BlackCat, also known as ALPHV, first appeared in November 2021 as a ransomware-as-a-service operation. Reporting described it as a Rust-based family used in double-extortion attacks against organizations worldwide.
Cisco Talos later compared a September 2021 BlackMatter intrusion with a December 2021 BlackCat intrusion and found overlapping command-and-control infrastructure, persistence methods, credential theft, and deployment tradecraft. Talos assessed with moderate confidence that the same affiliate likely conducted both attacks.
CISA released Malware Analysis Report AR21-189A on a DarkSide ransomware variant, detailing its encryption behavior, service creation, shadow copy deletion, C2 domains, and ransom note artifacts. CISA said it had no evidence that the analyzed variant was tied to the pipeline incident referenced in advisory AA21-131A.
DarkSide was identified as the ransomware family responsible for the Colonial Pipeline attack. This incident became a key reference point in later DarkSide technical reporting.
GuidePoint Security investigated an intrusion that began with a malicious Excel 4.0 macro delivering ZLoader and later progressed to DarkSide ransomware. The attackers spent several months on reconnaissance, lateral movement, exfiltration, and then deployed DarkSide broadly via Windows services and also targeted ESXi hosts.
DarkSide launched a ransomware-as-a-service affiliate program and advertised it on the Russian-language XSS and Exploit forums. The group said affiliates would receive 75% to 90% of ransom payments and sought access brokers with access to large U.S. businesses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
databreachtoday.com
Open sourceid-ransomware.blogspot.com
Open sourcesecurityscorecard.com
Open sourcebreached.company
Open sourcemedium.com
Open sourceus-cert.cisa.gov
Open sourcecybergeeks.tech
Open sourceguidepointsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.