ALPHV/BlackCat — Ransomware Profile
ALPHV (BlackCat) operated a sophisticated Rust-based RaaS platform responsible for major attacks including the Change Healthcare disruption. Disrupted by FBI in 2024.Also tracked as
BlackCat, Noberus, UNC4466, ALPHV-ng, ALPHV, Alpha Spider, ALPHV Ransomware Group
IntelFusions coverage (8)
- Rogue ransomware negotiator helped BlackCat extort his own clients 2026-07-14 · Ransomware
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16 · Ransomware
- Two U.S. Cybersecurity Professionals Plead Guilty to ALPHV BlackCat Ransomware Attacks 2026-02-16 · Ransomware
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16 · Cyber Incidents
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16 · Ransomware
- Inside BlackCat's Kill Chain: Picus Dissects ALPHV Ransomware TTPs After Change Healthcare Mega-Breach 2026-02-16 · Ransomware
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16 · Ransomware
- CISA and FBI Issue Joint Advisory on ALPHV BlackCat Ransomware Targeting Critical Infrastructure 2026-02-16 · Ransomware
Tools & malware
- ALPHV/BlackCat (Noberus) Ransomware/Encryptor (Rust)
- AnyDesk Remote access
- Brute Ratel Command-and-control / post-exploitation framework
- Cobalt Strike Command-and-control / post-exploitation framework
- GOST (GO Simple Tunnel) Tunneling / data exfiltration
- LaZagne Credential theft
- MEGAsync Data exfiltration
- Mimikatz Credential theft
- ngrok Remote access / tunneling
- PsExec Lateral movement / remote execution
- Rclone Data exfiltration
- Rubeus Credential theft (Kerberos)
- ScreenConnect Remote access
- StealBit Data exfiltration
Recent claimed victims
- ipmaltamira 2024-03-03
- Ewig Usa 2024-03-03
- Kumagai Gumi Group 2024-03-01
- SBM & Co 2024-03-01
- Petrus Resources Ltd 2024-03-01
- Allan Berger & Associates 2024-02-29
- Change Healthcare - Optum - UnitedHealth 2024-02-28
- Electro Marteix 2024-02-27
- verbraucherzentrale hessen 2024-02-27
- Angeles Medical Centers 2024-02-26
- S+C Partners 2024-02-26
- Worthen Industries 2024-02-24
- Family Health center 2024-02-23
- ANDFLA SRL 2024-02-23
- Hardeman County Community Health Center 2024-02-22
- Worthen Industries 2024-02-22
- Austen Consultants 2024-02-21
- Change Healthcare (UnitedHealth Group) 2024-02-21
- KHSS 2024-02-21
- VSP Dental 2024-02-18
- Prudential Financial 2024-02-16
- LoanDepot 2024-02-16
- Rush Energy Services Inc 2024-02-15
- ASA Electronics 2024-02-15
- The Source 2024-02-13
Vendor research
- #StopRansomware: ALPHV Blackcat (AA23-353A) CISA / FBI / HHS
- The many lives of BlackCat ransomware Microsoft
- BlackCat ransomware attacks not merely a byproduct of bad luck Sophos
- Threat Assessment: BlackCat Ransomware Unit 42 (Palo Alto Networks)
- BlackCat (ALPHV) ransomware linked to BlackMatter, DarkSide gangs BleepingComputer