CISA and FBI Issue Joint Advisory on ALPHV BlackCat Ransomware Targeting Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have released a joint cybersecurity advisory under the #StopRansomware initiative, warning organizations about the ongoing threat posed by ALPHV BlackCat ransomware affiliates targeting critical infrastructure sectors across the United States.

Over 1,000 Victims Worldwide

Since its emergence in November 2021, ALPHV BlackCat has compromised over 1,000 entities globally, with a significant concentration in healthcare, government, financial services, and critical manufacturing. The advisory notes that BlackCat-affiliated actors have demanded aggregate ransom payments totaling hundreds of millions of dollars, making it one of the most financially impactful ransomware operations in history.

Social Engineering for Initial Access

ALPHV affiliates have evolved beyond traditional phishing, conducting thorough open-source intelligence gathering to impersonate IT support staff. Affiliates contact employees via phone calls and SMS to create convincing scenarios requiring urgent technical support, manipulating targets into surrendering network credentials. This vishing-based initial access technique has proven highly effective against organizations with large helpdesk operations.

Sophisticated Technical Capabilities

Written in Rust, BlackCat was among the first major ransomware families to achieve true cross-platform capability across Windows, Linux, and VMware ESXi environments. The advisory highlights several key technical capabilities:

The FBI Disruption

In December 2023, the FBI disrupted ALPHV BlackCat's infrastructure, developing a decryption tool that enabled hundreds of victims to restore systems and avoid approximately $99 million in ransom payments. Despite this disruption, the advisory warns that affiliates have migrated to other ransomware platforms and the underlying TTPs remain a persistent threat.

Recommended Mitigations

CISA urges organizations to implement phishing-resistant multi-factor authentication, maintain offline encrypted backups, enforce network segmentation, and deploy endpoint detection and response solutions. The advisory particularly stresses the importance of training staff to recognize social engineering attempts — the primary vector exploited by BlackCat affiliates.

Read the full analysis on IntelFusions