Researchers and U.S. authorities warned that BlackCat/ALPHV ransomware operators and affiliates have repeatedly gained access to organizations through exposed remote administration paths, social engineering, and vulnerable internet-facing services. Microsoft documented the group's use of stolen credentials, compromised accounts, and a broad affiliate model, while CISA highlighted the growing abuse of remote monitoring and management (RMM) tools for stealthy persistence, lateral movement, and ransomware deployment.
SecurityScorecard tied those tactics to incidents affecting a U.S. county government and a vendor that manages local-government records, where investigators found signs of malicious SSH activity, exposed Telnet and OpenSSH services, possible use of ConnectWise/ScreenConnect, and suspicious transfers consistent with command-and-control or data exfiltration. In the records-management case, analysts assessed with moderate confidence that the disruption was caused by BlackCat ransomware or an attempted BlackCat attack, citing communications with infrastructure linked to prior malicious activity and behavior resembling BlackCat's exfiltration methods.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
CISA warned that malicious actors were increasingly exploiting legitimate remote monitoring and management software, including ConnectWise, for initial access. SecurityScorecard cited this warning as relevant to the vendor intrusion scenario.
A publicly accessible login page was available at the vendor's ConnectWise-related subdomain. The report says this suggested the organization's remote desktop service was exposed and could have been used with compromised credentials.
As of this date, some county customers' records remained inaccessible because of the vendor incident. This showed the operational impact continued into January.
A file named ConnectWiseControl.Client.exe containing the vendor subdomain connect.[vendordomain].com first appeared on VirusTotal. SecurityScorecard said the artifact indicated installation of a ConnectWise remote desktop client that may have enabled remote access.
News reporting stated that the records-management service disruption resulted from an unspecified cyberattack. This publicly characterized the December outage as a security incident.
A vendor managing digital records for U.S. county governments reported unusual activity and temporarily took its servers offline. This marked the start of a disruption that affected customer access to records.
From December 15 onward, SecurityScorecard observed a large volume of flows between a vendor IP and DigitalOcean IP 174.138.64[.]88, all using port 22. The report assessed this activity may represent data exfiltration and noted consistency with BlackCat's ExMatter behavior.
A vendor IP sent a 12.28 MB transfer to 159.65.203[.]252, far larger than any other observed transfer involving that IP. SecurityScorecard noted that several vendors had linked the destination to malicious activity and assessed the traffic may reflect VPN use to obscure attacker origin.
A U.S. county government announced that a recent cyber incident had disrupted its online services. Subsequent reporting indicated the incident strongly resembled a ransomware attack.
Another county IP address transferred 327.68 KB to 139.59.130[.]20. SecurityScorecard assessed that traffic from county IPs to this host could indicate command-and-control communications or data exfiltration.
A county IP address transferred 360.45 KB to 139.59.130[.]20. Multiple vendors had linked that destination IP to malware or malicious activity, and VirusTotal community members had observed SSH brute-force behavior from it.
IP address 120.57.42[.]39 transferred 129 KB to a county IP address. The report notes that no vendors had linked this IP to malicious activity at the time.
SecurityScorecard observed that between July 12 and September 9 there were 935 netflow records involving transfers of one gigabyte or more to or from county IP addresses. The report says multiple counterpart IPs in these flows had prior malicious or suspicious associations.
SecurityScorecard observed IP address 142.93.204[.]250 transfer 352.26 KB to a county IP address. The source IP had prior links to SSH brute-force activity and Mirai-related Telnet targeting.
A second Cryxos-linked HTML file containing another county government URL appeared and referenced local church and county emergency services content. The report says this may indicate impersonation or compromise of a community-linked webpage used in targeting.
A malicious HTML/JavaScript file containing a county government URL appeared on VirusTotal and was detected by multiple vendors as a Cryxos variant. The file used a Weebly domain and county-themed lure content, suggesting search-engine-driven targeting tied to social engineering.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcesecurityscorecard.com
Open sourcecisa.gov
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.