🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
ALPHV (BLACKCAT)

/actor/alphv-blackcat/  ·  0 intel reports

Year Established
2021
Attribution
Russia
Motivation
Financial
Modus Operandi (MO)
RaaS, Rust-based cross-platform ransomware, triple extortion, aggressive media relations
Primary Aliases
BlackCat, ALPHV, Noberus

ALPHV, known publicly as BlackCat, was a technically innovative and highly destructive ransomware-as-a-service operation that represented a significant evolution in ransomware sophistication. The group's ransomware was among the first major ransomware families written in the Rust programming language , enabling efficient cross-platform execution on Windows, Linux, and VMware ESXi, and providing inherent memory safety features that complicated security research and reverse engineering efforts.

ALPHV pioneered what researchers termed "triple extortion" , combining file encryption, data theft publication threats, and direct contact with the victim's customers, employees, or regulators to amplify pressure. In multiple cases, ALPHV notified the US Securities and Exchange Commission (SEC) when a publicly traded victim failed to disclose a breach within required timeframes , a bold escalation using regulatory compliance as a weapon against victims who were attempting to quietly negotiate ransom payment.

The group's most consequential attack was the February 2024 breach of Change Healthcare , the largest healthcare payment processing company in the United States. The attack disrupted prescription drug processing across thousands of US pharmacies for weeks, preventing patients from accessing medications and costing the healthcare system billions of dollars. Change Healthcare's parent company UnitedHealth Group ultimately paid a $22 million ransom , one of the largest ever paid , though the stolen data was subsequently offered for sale by an affiliate, suggesting an internal dispute.

In December 2023, the FBI seized ALPHV's infrastructure and released a decryptor, but ALPHV retaliated by publicly "unseizing" their site and removing restrictions on affiliate targets , including attacking hospitals. The group subsequently collapsed in March 2024 in what appeared to be an exit scam, with the administrator disappearing with funds owed to affiliates, driving displaced operators to competing platforms including RansomHub.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to ALPHV (BlackCat) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles