BlackCat — Malware Profile
BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, BlackCat has been used to target multiple sectors and organizations in various countries and regions in Africa, the Americas, Asia, Australia, and Europe.
MITRE ATT&CK techniques (21)
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1047 Windows Management Instrumentation
- T1059.003 Windows Command Shell
- T1069.002 Domain Groups
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1112 Modify Registry
- T1134 Access Token Manipulation
- T1135 Network Share Discovery
- T1222.001 Windows Permissions
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491.001 Internal Defacement
- T1548.002 Bypass User Account Control
- T1561.001 Disk Content Wipe
- T1570 Lateral Tool Transfer
- T1680 Local Storage Discovery
- T1685.005 Clear Windows Event Logs
IntelFusions coverage
- Inside BlackCat's Kill Chain: Picus Dissects ALPHV Ransomware TTPs After Change Healthcare Mega-Breach 2026-02-16
- CISA and FBI Issue Joint Advisory on ALPHV BlackCat Ransomware Targeting Critical Infrastructure 2026-02-16
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16
- Two U.S. Cybersecurity Professionals Plead Guilty to ALPHV BlackCat Ransomware Attacks 2026-02-16
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16
- Rogue ransomware negotiator helped BlackCat extort his own clients 2026-07-14
Attributed threat actors
- RansomHub machine-inferred link
- Scattered Spider
- ALPHV/BlackCat machine-inferred link