ALPHV (BlackCat) Ransomware

Description Summary

ALPHV, also known as BlackCat, is a sophisticated ransomware family first seen in late 2021. It operates on a Ransomware-as-a-Service (RaaS) model, allowing affiliates to use its malware for attacks. It employs double extortion techniques, encrypting systems and stealing sensitive files. The ransomware is written in Rust and uses AES or ChaCha20 encryption.

Threat Actor

The ransomware is operated by a group known as ALPHV or BlackCat, with affiliates using advanced social engineering techniques to gain initial access.

Technical Indicators

Encryption Extension
RECOVER-(seven-digit extension) FILES.txt
Encryption Algorithm
AES or ChaCha20
Ransom Note Name
file.txt
Targeted Industries
Financial services, Healthcare, Manufacturing, Government
First Seen
November 2021
Last Seen
February 2024 — DEFUNCT (exit scam, March 2024)
Geographical Location
Worldwide, with significant activity in the United States

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1566.001 Spearphishing Attachment
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Data Encrypted for Impact (Rust + ChaCha20/AES)