• Also known as: ALPHV, AlphaV, Noberus
  • First observed: November/December 2021
  • Suspected origin: Russia (Russian-speaking operators, believed to be linked to DarkSide/BlackMatter/REvil lineage)
  • Model: Ransomware-as-a-Service (RaaS)
  • Status: No longer operating as a group since a March 2024, though former operators and affiliates are believed to still be active under other names

 

Origins

Barracuda's threat research team noted that ALPHV's origins trace back to GandCrab, which shut down voluntarily in 2019 and rebranded to REvil, which operated until an FBI disruption in 2021. While we aren’t certain that REvil rebranded into DarkSide, many of DarkSide's affiliates and tactics carried over from REvil.

DarkSide didn't withstand the Colonial Pipeline attack, it resurfaced briefly as BlackMatter. What came after was BlackCat. A security researcher and TechFinitive analyst, Davey Winder, noted that an FBI advisory published in April 2022 found enough evidence to link ALPHV/BlackCat's developers to the DarkSide and BlackMatter operations, all of which conducted business on Russian-language dark web criminal forums. BleepingComputer, which covered the group's emergence, reported that The Record published an interview in which the ALPHV/BlackCat gang confirmed the group's affiliation with the earlier DarkSide/BlackMatter operation.

BleepingComputer's Lawrence Abrams, reporting just weeks after BlackCat's launch, situated the group within a pattern of top-tier RaaS operations that repeatedly shut down under law enforcement pressure and resurfaced under new names. In that same reporting, ALPHV told The Record that as former DarkSide/BlackMatter affiliates, they'd been hurt financially when Emsisoft released a free decryptor for BlackMatter victims. However, Emsisoft threat analyst Brett Callow argued it was more likely that ALPHV simply was DarkSide/BlackMatter under a new name, suggesting the group was "attempting to distance themselves from that brand due to the reputational hit" the decryptor episode caused.

Abrams also noted that BlackCat's first attack was similar to DarkSide's Colonial Pipeline attack, an attack on fuel infrastructure, BlackCat's affiliates struck German fuel distributors Oiltanking and Mabanaft.

Furthermore, Aaron Sandeen, writing for DarkReading in "Everything You Need To Know About BlackCat (AlphaV)," reported that the group had breached more than 60 organizations within just its first months of activity, attacking government agencies, healthcare systems, and public utilities, evidence, Sandeen argued, that BlackCat was treating every sector as fair game.

A 2025 peer-reviewed study, "Inside ransomware groups: An analysis of their origins, structures, and dynamics", backs up this rebrand-and-resurface pattern, the academic paper places BlackCat alongside Conti and LockBit as one of the three most prominent ransomware groups of the past five years, and confirms that BlackCat is a rare case among the three of a group that both succeeded earlier operations (DarkSide, BlackMatter, and REvil) and later inherited members from those predecessor groups.

 

What made BlackCat technically different

Microsoft's threat intelligence team, which tracked the group from its earliest activity, explained why it stood out. First observed in November 2021, BlackCat made headlines as one of the first ransomware families written in the Rust programming language, a choice intended to help the payload evade detection by security tools not yet equipped to analyze Rust binaries. Sandeen's analysis supported that assessment, crediting the Rust codebase with giving BlackCat's operators greater stability and cross-platform flexibility, and noting that Rust adoption has become common among other ransomware groups.

Microsoft's researchers also documented BlackCat's capabilities besides their language choice. The payload was built to hit multiple platforms at once, Microsoft observed successful attacks against Windows and Linux devices as well as VMware, and came with features that gave affiliates room to customize each attack to the system they'd broken into. Sandeen's reporting adds that BlackCat's executables were also tailored to each target and capable of encrypting data using four encryption methods, part of what he described as the group's reputation for sophisticated, individualized attack patterns.

The group also ran an affiliate model, which meant its attackers could differ in skill and background from one incident to the next. Microsoft found that at least two known affiliate groups adopted BlackCat, one previously known for deploying Ryuk, Conti, and Hive, and another for deploying Ryuk, REvil, BlackMatter, and Conti, meaning "no two BlackCat 'lives' or deployments might look the same," since different affiliates brought different tactics, techniques, and procedures. By mid-2022, Microsoft had already observed BlackCat's activity across various countries and regions in Africa, America, Asia, and Europe. Sandeen also noted the group's public leak site as an example of that operational sophistication, noting it let visitors search the group's cache of stolen data by victim name, password, and document type.

The peer reviewed study adds that while Conti generally stuck to double extortion (encrypting and threatening to leak data), and LockBit progressed to triple extortion by adding DDoS threats, BlackCat alone among the three groups escalated to quadruple extortion, meaning they also threatened a victim's third-party suppliers and business partners directly. BlackCat also stood out for weaponizing U.S. securities law as a pressure tactic, after breaching lending-software firm MeridianLink in 2023 and receiving no ransom payment, the group filed a complaint against its own victim with the Securities and Exchange Commission for failing to disclose the breach. The paper also documents an episode in which BlackCat exfiltrated data from Reddit without bothering to encrypt any files, relying on the threat of a leak rather than the disruption of an actual encryption event.

 

Techniques and targets

BlackCat operates on an affiliate model rather than a single fixed playbook, that way any attack depends on who was running it. Davey Winder described the group as favoring two initial access methods, that is, exploiting unpatched vulnerabilities, and targeted spearphishing aimed at specific employees and directors to harvest login credentials. On the vulnerability side, Winder noted that the group liked aging Microsoft Exchange Server flaws along with older Windows vulnerabilities and weaknesses in firewalls and VPNs. Sandeen's analysis found the same emphasis on stolen or leaked credentials as an entry point, pointing to a 2021 industry estimate that roughly 20,000 security incidents began with compromised credentials, and describing BlackCat's intrusion pattern as quietly mapping the victim's network and escalating account access before building a customized payload and disabling security and backup systems.

Winder's reporting also laid out the pressure campaign affiliates used once they'd gained access, describing it as a triple-extortion model which includes encrypting the victim's data, exfiltrating it beforehand and threatening exposure via a public leak site, and launching denial-of-service attacks. Access to the malware and its control panel was granted only after affiliates were vetted through criminal forums, reinforcing that the RaaS model functioned much like a criminal franchise rather than a single hacking crew. The peer reviewed study’s affiliate-vetting findings line up with this, noting that BlackCat interviewed and screened prospective affiliates before granting them control-panel access, and that affiliates who underperformed could be removed from the program while top earners could be promoted to an "Affiliate Plus" tier with access to extras like DDoS capability.

Winder's reporting connects the group to the 2022 breach of American defense contractor NJVC, and to some high-profile 2023 attacks including MGM Resorts International (and its casino operations), the Northwest Florida state court system, and Western Digital. Notably, the MGM breach was widely attributed in media coverage to Scattered Spider, a newer threat-actor group but Winder identifies Scattered Spider as an ALPHV/BlackCat affiliate rather than a rival operation.

 

The FBI steps in

According to a Congressional Research Service brief, in December 2023 the Department of Justice announced it had disrupted the operations of the BlackCat/ALPHV/Noberus ransomware group, developing a decryption tool that saved victims from paying an estimated $68 million in ransom demands.

However, the disruption didn't destroy the group. Investigative journalist Brian Krebs, whose site KrebsOnSecurity has tracked ransomware operators, reported that in the aftermath, BlackCat responded by re-forming and increasing affiliate commissions to as much as 90 percent, while formally declaring it was removing any restrictions or discouragement against targeting hospitals and healthcare providers. The peer reviewed study documents this as well, framing it as part of a pattern it found across ransomware groups, when hit with law enforcement action, groups tend to retaliate rather than retreat.

 

The Change Healthcare attack

On February 21, 2024, UnitedHealth Group disclosed that its subsidiary Change Healthcare, which processes about half of all medical claims in the United States for approximately 900,000 physicians, 33,000 pharmacies, 5,500 hospitals, and 600 laboratories, was under attack. CEO Andrew Witty's congressional testimony explained that BlackCat used compromised credentials to remotely access a Change Healthcare Citrix portal enabling remote desktop access.

The outages didn't just hit Change Healthcare's own systems, BankInfoSecurity reported that Optum took more than 100 connected healthcare systems offline as part of its recovery effort, leaving hundreds of providers, including U.S. military pharmacies worldwide, unable to receive reimbursement for prescriptions. The disruption drew attention from lawmakers and industry groups, and the U.S. Department of Health and Human Services said it was in close contact with UnitedHealth Group over the cash-flow strain being reported by hospitals, doctors, and pharmacies nationwide.

Learn more: Going deeper: The Change Healthcare attack

 

The exit scam

On March 3, 2024, a forum user going by "Notchy," an affiliate of the ALPHV/BlackCat, claimed that they had been scammed out of their share of the $22 million ransom payment. GovInfoSecurity's reporting on the affiliate dispute noted that Optum paid the $22 million to prevent both a data leak and to obtain the decryption key, after which BlackCat's administrators suspended Notchy's account, stalled him through the group's Tox messaging channel, and drained the cryptocurrency wallet. Notchy shared the wallet address he said was tied to ALPHV, which blockchain analysts calculated had received roughly 1,401 bitcoins, worth more than $92 million.

Furthermore, GovInfoSecurity reported that the administrators of the BlackCat ransomware-as-a-service group claimed law enforcement had shut down their operation, while experts and affiliates accused the group's leadership of running an exit scam, staging a fake takedown notice on their Tor-based leak site that claimed the FBI had seized it as part of a "coordinated law enforcement action."

BlackCat's leadership came with a second claim the same week, that the entire operation was closing for good. A Russian-language post attributed to a forum user known as "Rivka" said the group would sell its source code, pricing it at roughly $5 million and blaming federal law enforcement for the shutdown. Krebs on Security summarized the underworld reaction, quoting one reader's assessment that BlackCat had "stabbed their partner/client in the back and left them potentially holding a bag of stolen data" while damaging the broader ransomware-as-a-service business model, since "you don't throw rocks in the fishing hole; it scares the fish."

 

Where BlackCat's operators are now

Formally, ALPHV/BlackCat no longer exists as an active group. BlackCat’s history suggests it is likely to regroup under a new name once law enforcement heat and affiliate distrust subside. The peer reviewed study mentioned a newer group called Cicada3301, which the paper notes shares enough operational similarities with BlackCat to be suspected of picking up where its predecessor left off. The paper also notes that no specific leading member of BlackCat has ever been publicly identified. That anonymity may partly explain why, when LockBit's own spokesperson taunted the industry after BlackCat's collapse, he could frame its disappearance almost as a personal victory, stating, "Previously, the only worthy competitor as I saw it was AlphV/BlackCat. But now they are gone... I don't see a single worthy competitor."

 

FAQs

What is ransomware-as-a-service (RaaS)?

It's a business model where a group builds and maintains ransomware, then leases its use to independent "affiliates" who carry out attacks and split the profits.

 

How do most ransomware attacks start?

The two most common entry points are phishing emails that trick someone into handing over credentials and exploitation of unpatched software vulnerabilities.

 

Why do ransomware groups keep rebranding under new names?

Rebranding lets operators evade law enforcement attention while often keeping the same people, tools, and affiliate relationships.

 

How is a "double extortion" attack different from basic ransomware?

Basic ransomware just encrypts files, while double extortion also steals the data first and threatens to publish it even if the victim restores from backups.