BlackCat / ALPHV
Aliases: ALPHV, BlackCat, Noberus
Source profile review date: 2026-05-31
Research status: Existing researched dossier
Executive summary
BlackCat/ALPHV is a mature RaaS profile that combined affiliate operations, social engineering, data theft, encryption and aggressive extortion.
BlackCat/ALPHV is analytically important because it shows that modern ransomware is not only about a binary, but about access, identity, data, public pressure, negotiation and crisis disruption.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Executive summary
BlackCat, also known as ALPHV and in some sources Noberus, is a reference profile for modern ransomware-as-a-service. The group became known for technical flexibility, an affiliate model, data theft, encryption and aggressive extortion. The dossier remains relevant even when the brand is less visible, because affiliates, social-engineering methods and operational routines can move to other groups.
The leadership lesson is that BlackCat-like incidents often combine multiple forms of damage: outage, data-breach risk, reputational pressure, communication chaos, customer impact and legal notification duties. The ransomware binary is only one piece of evidence; the real incident lies in the route from initial access to control over data and recovery processes.
CISA/FBI describe ALPHV BlackCat affiliates using Evilginx2 for adversary-in-the-middle phishing, stealing MFA material, credentials and session cookies, and extorting victims after data exfiltration without always deploying ransomware. Identity and session security are therefore central to this profile.
Group and development
BlackCat/ALPHV developed as a RaaS ecosystem where operators and affiliates did not always leave the same technical footprint. The brand supplied reputation and extortion infrastructure, while affiliates could obtain access through phishing, stolen credentials, vulnerable external services, social engineering or other routes.
Law-enforcement actions and infrastructure disruption affected ALPHV visibility, but that does not mean the threat disappears. Ransomware markets are fluid: affiliates, tooling, stolen access and negotiation knowledge can return elsewhere.
The group became widely known through incidents at large organisations, including public reporting around MGM Resorts and Change Healthcare. These cases show that impact can extend far beyond IT: reservation systems, healthcare claims, payment processes, customer service, physical operations and public communication can be affected together.
Methods and attack chain
Investigation starts with identity and social engineering. Check helpdesk processes, password resets, MFA registrations, new devices, SSO events, conditional-access decisions, session tokens, OAuth consents and suspicious login locations.
After initial access, privilege build-up and discovery often follow. Relevant traces include domain enumeration, admin-group changes, credential access, remote management, PowerShell, WMI, RDP, PsExec-like behaviour, security-tool impairment and access to file servers or cloud storage.
Data theft is an independent incident phase. Look for staging directories, archives, cloud-upload tools, large downloads, unusual API calls, access to HR, finance, healthcare or customer data, and traffic to unknown infrastructure.
Encryption and publication pressure must be tied to negotiation and communication behaviour. Collect ransom notes, file changes, actor communication, leak-site claims, publication times and proof of security-tool tampering.
Attack pattern from public cases
BlackCat/ALPHV became known as a RaaS operation in which affiliates combined identity, social engineering, data theft and encryption. In public incidents, the first value was not always malware but access through accounts, sessions, helpdesk processes or cloud environments.
CISA/FBI name AiTM phishing with Evilginx2 and theft of MFA material, credentials and session cookies. Defence must therefore inspect login context: new MFA methods, reset requests, new devices, suspicious sessions and cloud downloads.
ALPHV-like extortion can be data-first. Affiliates can steal data and extort victims without always deploying ransomware. No encrypted server does not automatically mean there is no serious incident.
Lessons from major public cases are concrete: helpdesk verification, phishing-resistant MFA, session management, cloud logging and data-download monitoring are core controls.
Known IOCs and artefacts
CISA AA23-353A describes Evilginx2 use by ALPHV/BlackCat affiliates for adversary-in-the-middle phishing. This is not a simple hash but an important method artefact: watch suspicious login proxies, abnormal user agents and sessions that appear to bypass MFA.
The advisory names theft of MFA data, credentials and session cookies. Concrete signals are new MFA registrations, suspicious reset flows, impossible travel, new devices and sessions that remain active after password changes.
Cloud artefacts matter: mailbox rules, OAuth consents, SharePoint/OneDrive download spikes, delegated access and audit-log gaps can prove data-first extortion.
Endpoint artefacts remain relevant when affiliates use remote management, archiving, credential access or EDR tampering. Always tie them to the identity that started the process and the data accessed afterwards.
Victims and historical context
Historical ALPHV/BlackCat victim context includes major public incidents and many smaller claims. The important point is not only the victim name but the impact form. MGM showed how social engineering and identity abuse can disrupt operations. Change Healthcare showed how supply-chain impact in healthcare and payments can become large when a central service provider is hit.
Record per victim: sector, country, claim date, source, impact type, possible data types, indications of social engineering, cloud or identity involvement and whether encryption was actually established. This prevents treating every BlackCat mention as the same technical scenario.
Detection and follow-up
Priorities are phishing-resistant MFA, strong helpdesk verification, conditional access, logging of MFA changes, session-risk detection, restriction of OAuth consents, least privilege, EDR hardening, exfiltration monitoring and crisis-communication exercises.
For a BlackCat-related claim, triage revolves around four questions: is the claim real, which identity was abused, which data was affected and how reliable is recovery? Only then does the exact ransomware variant become relevant for leadership.
Deep forensic dossier
BlackCat/ALPHV requires an investigation that handles identity, cloud and endpoint together. When affiliates use AiTM phishing or helpdesk manipulation, first actor activity can look like a legitimate session.
Helpdesk and process logs are as important as EDR. Ask for tickets, calls, reset requests, identity verification, escalations, exceptions and temporary access. Strong MFA can be undermined by weak operational process.
Cloud investigation must include mailboxes, document platforms and app consents. Check mailbox rules, delegated access, OAuth consents, service principals, SharePoint or OneDrive downloads, audit-log gaps and external sharing.
Endpoint investigation remains necessary but should not be the only lens. Look for remote management tooling, credential access, PowerShell, archiving, staging, EDR tampering and lateral movement, then link every trace to identity events.
For crisis communication, BlackCat is a clear example of reputational pressure. Actor communication, media attention and customer questions can escalate faster than technical analysis.
After containment, test whether the same attack is still possible. Have helpdesk procedures changed, MFA methods been cleaned, sessions revoked, OAuth consents restricted, privileged accounts separated and exfiltration alerts improved?
What to watch for
With BlackCat/ALPHV, identity, social engineering and data theft are central. Watch helpdesk requests, password resets, new MFA methods, suspicious sessions, new devices, cloud downloads and abnormal privilege use.
Important signals include logins shortly after a reset, MFA registrations that do not match the user, new OAuth consents, mailbox rules, large SharePoint or OneDrive downloads, remote management tooling, data archiving and EDR alerts about credential access or tampering.
BlackCat/ALPHV showed that reputational pressure and business disruption can combine. Technical detection must be paired with strong helpdesk process and crisis communication.
How to defend against BlackCat/ALPHV
Strengthen identity first. Use phishing-resistant MFA for administrators, restrict MFA reset processes, enforce strict helpdesk verification, monitor new MFA methods and revoke suspicious sessions immediately.
Protect cloud data. Enable audit logging, monitor large downloads, restrict app consents, check mailbox rules and watch external sharing. Much modern extortion focuses on data before encryption becomes visible.
Train helpdesk and service desk teams against social engineering. An attacker who obtains a reset or MFA change can bypass technical controls; procedures must include callback to known numbers, management approval for sensitive resets, exception logging and fast security escalation.
Victim pattern and lessons
BlackCat/ALPHV is publicly linked to large incidents where identity, business processes and reputation were central. The lesson is that ransomware is not only an IT problem: customers, suppliers, media, regulators and leadership become part of the response.
For organisations with much cloud data, the main lesson is that extortion without broad encryption can already be severe. If HR, finance, healthcare or customer data is downloaded through cloud sessions, legal and reputational risk exists even without encrypted servers.
Use BlackCat/ALPHV as a test for identity governance: who may reset accounts, who may change MFA, which sessions stay valid and who sees sudden data downloads?
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| tool/method | Evilginx2 adversary-in-the-middle phishing | CISA AA23-353A | Used by ALPHV/BlackCat affiliates to capture MFA/session material |
| credential artifact | stolen MFA data, credentials and session cookies | CISA AA23-353A | Identity-first intrusion signal |
| cloud artifact | new MFA method / suspicious session / OAuth consent / mass cloud download | CISA AA23-353A defensive context | Behavioral artifacts for BlackCat/ALPHV-style access |
| case context | MGM Resorts / Change Healthcare public incident context | Public reporting and CISA ALPHV context | Use as victimology and impact lesson, not as an IOC |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.