Description Summary
Rust RaaS with strong ALPHV/BlackCat overlap; assessed possible rebrand/successor.
Threat Actor
Assessed possible ALPHV rebrand, partnership, or modified-code successor; RAMP-advertised RaaS.
Technical Indicators
Encryption Extension
Not publicly reported
Encryption Algorithm
ChaCha20 (Rust; Windows + Linux/ESXi) — strong ALPHV/BlackCat command/file-naming overlap
Ransom Note Name
Not publicly reported
Targeted Industries
SMBs across construction, IT, legal, retail, healthcare, transport, telecom, hospitality, finance, real estate, manufacturing
First Seen
June 2024
Last Seen
Active
Geographical Location
Global
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |