BlackCat/ALPHV affiliates carried out targeted double-extortion attacks by stealing data and deploying ransomware across Windows, Linux, and VMware ESXi environments, using a Rust-based payload that supports extensive customization. Reporting from Microsoft, Netskope, and Forescout shows the group gaining initial access through several routes, including compromised RDP credentials, exploitation of an unpatched Exchange server, an Internet-exposed SonicWall firewall, and a contractor account compromised via a malicious browser extension that led to virtual desktop access without MFA. After entry, operators escalated privileges, enumerated domains and devices, dumped credentials, and moved laterally with legitimate tools such as PsExec before staging broad encryption operations.
In one analyzed intrusion, attackers used a compromised domain account to push the ExMatter exfiltration tool and the BlackCat payload to more than 2,000 machines, with ExMatter collecting selected file types and sending them over WebDAV to attacker-controlled infrastructure. Researchers also documented BlackCat features including self-propagation via NetBIOS discovery, shadow copy deletion, service termination, event log clearing attempts, and ESXi-specific actions such as stopping virtual machines and deleting snapshots. Separate technical analysis and tooling published by defenders showed that BlackCat binaries embed configurable options for ransom notes, propagation, encryption behavior, and virtualization-focused disruption, underscoring how affiliates adapt the malware to different victim environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In September 2022, BlackCat claimed to have breached a contractor serving the U.S. Department of Defense and other government agencies.
Netskope reports the BlackCat ransomware payload used in its analyzed incident was compiled in July 2022, indicating use of a newer variant requiring an access token to decrypt configuration.
Forescout states the ransomware deployment in the analyzed VMware ESXi intrusion occurred on March 17, 2022.
Microsoft and other referenced reporting state that BlackCat/ALPHV was first observed or discovered in November 2021 as a ransomware-as-a-service operation.
After escalating privileges and moving laterally, the attackers used PsExec and a compromised domain account to deploy ExMatter and the BlackCat ransomware payload to more than 2,000 machines.
In the targeted BlackCat incident analyzed by Netskope, attackers compromised a contractor account using a malicious browser extension and used the lack of MFA to access a virtual desktop inside the corporate network.
In the Netskope-analyzed intrusion, the attackers set up the ExMatter server used for WebDAV-based data exfiltration one day before the attack.
Microsoft published analysis describing BlackCat as a prevalent RaaS threat, identifying affiliates DEV-0237 and DEV-0504 and detailing observed intrusion chains using Exchange exploitation or compromised RDP credentials.
A GitHub project published a static configuration extractor for BlackCat/ALPHV samples across Windows, Linux, and ESXi, enabling extraction of embedded config data.
In an analyzed incident, an ALPHV affiliate gained initial access through an internet-exposed SonicWall firewall and later moved to encrypt a VMware ESXi virtual farm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcenetskope.com
Open sourcemicrosoft.com
Open sourcegithub.com
Open sourceforescout.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.