BlackCat
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AlphV, also known as BlackCat, is a ransomware group that emerged in late 2021 operating as a ransomware‑as‑a‑service affiliate model. The group’s malware is written in the Rust programming language, which contributes to its evasion capabilities and cross‑platform functionality. AlphV employs double extortion tactics, encrypting victim data while threatening to publish stolen information unless a ransom is paid. Public reporting indicates the actors primarily seek financial gain and have targeted a range of sectors including healthcare, education, finance, and critical infrastructure across multiple regions. Initial access is frequently achieved through phishing campaigns, exploitation of vulnerable remote‑access services such as VPNs, or the use of compromised credentials. Once inside a network, the group utilizes tools like Mimikatz for credential dumping and leverages legitimate administration utilities for lateral movement and data staging.
A concrete example of AlphV’s activity is the ransomware attack on Academy Mortgage disclosed on 14 May 2023, during which the group exfiltrated customer, financial and personal data before encrypting systems. The breach led to a class‑action lawsuit alleging inadequate protection of personal information for over 284,000 individuals, which Academy Mortgage settled for approximately two million dollars. This incident followed the company’s earlier settlement of federal charges related to mortgage underwriting fraud, illustrating how AlphV can exploit entities already under regulatory scrutiny. The attack exemplifies the group’s pattern of combining data theft with encryption to increase pressure on victims to pay the ransom. While the Academy Mortgage case is one of the publicly reported operations, AlphV has been linked to numerous other incidents affecting organizations worldwide. These observed behaviors collectively define AlphV (BlackCat) as a financially motivated ransomware threat that relies on Rust‑based malware, double extortion, and common initial‑access vectors to achieve its objectives.
Incidents
Attributed incidents are available to members.
1 incident