Description Summary
ALPHV, also known as BlackCat, is a sophisticated ransomware family first seen in late 2021. It operates on a Ransomware-as-a-Service (RaaS) model, allowing affiliates to use its malware for attacks. It employs double extortion techniques, encrypting systems and stealing sensitive files. The ransomware is written in Rust and uses AES or ChaCha20 encryption.
Threat Actor
The ransomware is operated by a group known as ALPHV or BlackCat, with affiliates using advanced social engineering techniques to gain initial access.
Technical Indicators
Encryption Extension
RECOVER-(seven-digit extension) FILES.txt
Encryption Algorithm
AES or ChaCha20
Ransom Note Name
file.txt
Targeted Industries
Financial services, Healthcare, Manufacturing, Government
First Seen
November 2021
Last Seen
February 2024 — DEFUNCT (exit scam, March 2024)
Geographical Location
Worldwide, with significant activity in the United States
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 4 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| T1566.001 | Spearphishing Attachment | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 4 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| T1486 | Data Encrypted for Impact (Rust + ChaCha20/AES) |