BlackCat/ALPHV operators were linked to intrusions that began with exploitation of vulnerable Microsoft Exchange servers, including CVE-2021-31207 in ProxyShell-style activity and other unpatched Exchange exposures. Investigators observed the attackers planting ASPX web shells, using IIS worker processes to launch PowerShell, and establishing persistence and remote access with tools including MobaXterm. In one case, a tampered libeay32.dll was downloaded to sideload Cobalt Strike, while post-compromise activity included credential theft through Mimikatz or LSASS dumping with Process Hacker, along with account and network discovery using SoftPerfect Network Scanner, NetScan, BloodHound, Inveigh, and CrackMapExec.
Before encryption, the operators compressed targeted data with WinRAR or 7-Zip and exfiltrated files through rclone, MEGAsync, and in some cases FileZilla or WinSCP. Lateral movement and staging were carried out over SMB, including use of SysVol shares and local paths such as C:\Windows\debug, followed by permission changes, shadow copy deletion, recovery disabling, and log clearing. Researchers also identified a newer BlackCat variant with previously undocumented command-line options including --safeboot and --sleep-restart, underscoring the group’s continued ability to target Windows, Linux, and VMware ESXi environments while pairing encryption with data theft and Tor-based extortion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
BlackCat/ALPHV, a Rust-based ransomware-as-a-service family targeting Windows, Linux, and VMware ESXi systems, appeared in November 2021.
MITRE ATT&CK published the software entry S0488 for CrackMapExec, a tool later referenced in BlackCat intrusion activity for credential dumping and lateral movement.
SecurityScorecard reported a newer BlackCat version that introduced previously undocumented command-line parameters including --safeboot and --sleep-restart, indicating updated ransomware functionality.
Before encryption in the SecurityScorecard investigation, the attackers compressed targeted files with WinRAR or 7-Zip and exfiltrated data using rclone and MEGAsync, with FileZilla and WinSCP also observed in the environment.
In the SecurityScorecard case, the operators dumped credentials with Mimikatz or an LSASS dump via Process Hacker, moved laterally over RDP, and used SoftPerfect Network Scanner to identify additional targets.
SecurityScorecard described a DFIR investigation in which BlackCat operators gained access through an unpatched Microsoft Exchange server containing multiple web shells, then installed tools including MobaXterm, Process Hacker, and cURL.
The ransomware was staged on SysVol Share and in C:\Windows\debug, permissions were adjusted with icacls.exe and net share, and BlackCat then deleted shadow copies, disabled recovery, cleared logs, and encrypted files while dropping a ransom note claiming data theft.
The attackers conducted account and network discovery with tools including NetScan, BloodHound, CrackMapExec, and Inveigh, then spread modified DLLs to remote machines over SMB.
After web shell access, the attackers used PowerShell to download a tampered libeay32.dll from 5[.]255[.]100[.]242 and executed it with rundll32.exe to load a Cobalt Strike stager.
In the Trend Micro-investigated incident, attackers gained initial access to a Microsoft Exchange environment by exploiting CVE-2021-31207 in ProxyShell-style activity and wrote ASPX web shells to the server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcetrendmicro.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.