Inactive ransomware operator
← All groupsALPHV/BlackCat
aka ALPHV, BlackCat, Noberus · 931 victims indexed · first seen 5 years ago · last activity 2 years ago
At a glance
- Status
- inactive
- Aliases
- ALPHV, BlackCat, Noberus
- First seen
- 5 years ago
- Last activity
- 2 years ago
- Onion sites
- 4 known endpoints
- Primary sector
- Healthcare · 34 hits
About
References
53 linksExternal sources curated by the MISP threat-intel community.
- malpedia.caad.fkie.fraunhofer.de/details/win.blackcat
- 1-id--ransomware-blogspot-com.translate.goog/2021/12/blackcat-ransomware.html?_x_tr_enc=1&_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=ru
- medium.com/s2wblog/blackcat-new-rust-based-ransomware-borrowing-blackmatters-configuration-31c8d330a809
- github.com/f0wl/blackCatConf
- sentinelone.com/labs/blackcat-ransomware-highly-configurable-rust-driven-raas-on-the-prowl-for-victims/
- varonis.com/blog/alphv-blackcat-ransomware
- intrinsec.com/alphv-ransomware-gang-analysis
- unit42.paloaltonetworks.com/blackcat-ransomware/
- cyber.gov.au/acsc/view-all-content/advisories/2022-004-acsc-ransomware-profile-alphv-aka-blackcat
- microsoft.com/en-us/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware/
- blog.emsisoft.com/en/40931/ransomware-profile-alphv/
- blog.group-ib.com/blackcat
- blog.talosintelligence.com/2022/03/from-blackmatter-to-blackcat-analyzing.html
- blogs.vmware.com/security/2022/09/esxi-targeting-ransomware-the-threats-that-are-after-your-virtual-machines-part-1.html
- killingthebear.jorgetesta.tech/actors/alphv
- krebsonsecurity.com/2022/01/who-wrote-the-alphv-blackcat-ransomware-strain/
- news.sophos.com/en-us/2022/07/14/blackcat-ransomware-attacks-not-merely-a-byproduct-of-bad-luck/
- query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE54L7v
- securelist.com/a-bad-luck-blackcat/106254/
- securelist.com/new-ransomware-trends-in-2022/106457/
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
8 techniques · 7 tacticsTactics
Indicators of compromise
CVEs exploited
Known tools
File hashes
- SHA256 847fb7609af3e58e50fc2e63e6b5b87bd5c3f7c5d115cf5c0e0a8ed85c5cfaf5BlackCat payload (Rust)
Domains
- alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion
Detection · YARA rules
1 ruleRansom_Win_BlackCat
YARA rule from ATR/Trellix: ransomware/Ransom_Win_BlackCat_public.yar
source: ATR/Trellix
Recent victims
Loading…
Onion infrastructure
4 known- http://2cuqgeerjdba2rhdiviezodpu3lc4qz2sjf4qin6f7std2evleqlzjid.onion
- http://alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion/api/blog/all/0/6
- http://vqifktlreqpudvulhbzmc5gocbeawl67uvs2pttswemdorbnhaddohyd.onion/search
- http://alphvuzxyxv6ylumd2ngp46xzq3pw6zflomrghvxeuks6kklberrbmyd.onion/api/blog/brief/0/100
Source
Updated 2 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
