Also known as: blackcat
The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote their affiliate program, offering other actors the opportunity to engage in a 'new type of ransomware family' developed from scratch using the Rust programming language.<BR> <BR> Some clear evidence indicates that the actors behind this new ransomware are not new to cybercrime, and there were links to other affiliate programs such as DarkSide, BlackMatter, and REvil. (After several attacks against large companies, these groups faced pressure and arrests, necessitating the termination of their operations).<BR> <BR> As a security measure, the operators of ALPHV implemented the requirement for the execution of the ransomware payload by providing an 'access token,' which is supplied by the owners of the Ransomware-as-a-Service to the affiliate. This token is added to the victim's ransom note so that they can contact the threat actor responsible for encrypting the data.<BR> <BR> ALPHV affiliates employ double and triple extortion techniques, meaning the publication of the company's name on leak sites, threats of data leakage, and lastly, threats of DDoS attacks against the organization.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 731 4 ransom note(s) on file
Objectives
Executive Summary
The ALPHV/BlackCat ransomware group is a medium-sophistication, criminal organization primarily motivated by organizational gain through ransomware and financial exploitation. First seen in September 2021, they operate an affiliate program offering a Rust-based ransomware family to other actors. ALPHV is known for double and triple extortion techniques, including data leakage and DDoS threats.
Goals & Targeting
ALPHV's strategic objectives are centered on achieving organizational gain through ransomware operations and financial exploitation. Their targeting profile suggests a focus on sectors and organizations that can be pressured into paying significant ransoms, indicating a calculus based on the potential financial return and the perceived resilience of their targets. Typical victims include large companies with sensitive data and a strong incentive to maintain operational continuity, making them more susceptible to the threats posed by ALPHV's extortion techniques.
Enhanced Description
ALPHV affiliates have been observed employing double and triple extortion techniques. These include the publication of a company's name on leak sites, threats of data leakage, and, finally, threats of DDoS attacks against the organization. This multi-faceted approach to extortion amplifies the pressure on victims to pay the ransom, reflecting the group's adaptability and willingness to evolve their tactics to maximize their gains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ALPHV's campaign patterns have involved targeted ransomware attacks against large companies across various sectors, with an operational tempo that suggests a high volume of affiliate activity. The group's use of double and triple extortion techniques indicates a sophisticated approach to maximizing the pressure on victims. Notable past operations have included the compromise of significant organizations, resulting in substantial ransom demands and, in some cases, the publication of exfiltrated data on leak sites.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on ALPHV is moderate to high, given the group's visible activity on Dark Web forums and the existence of clear evidence linking them to other ransomware groups. However, information gaps exist regarding the full scope of their operations, the identities of key individuals, and the exact mechanisms of their affiliate program. Further intelligence gathering is necessary to fully understand ALPHV's capabilities and to anticipate their future tactics.
No techniques linked yet.
No tools linked yet.
New ransomware
Imported from MISP event #455 (57174526-23d8-4895-8c08-4ed1950d210f).
Apr 20, 2016
TLP:CLEARNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics