Avatier

Threat actor

ALPHV Blackcat

Also known as BlackCatSource [1]

FBI, CISA and HHS describe ALPHV Blackcat as a ransomware-as-a-service operation whose affiliates have experience with ransomware and data extortion.Source [1]

What authorities and investigators report

  • The advisory says affiliates posed as company IT or help-desk staff and used phone calls or SMS messages to obtain credentials from employees.Source [1]
  • It says affiliates used the open-source adversary-in-the-middle framework Evilginx2 to obtain MFA credentials, login credentials and session cookies.Source [1]
  • It says affiliates moved or exfiltrated victim data before deploying the ransomware, and that some affiliates extorted victims without deploying ransomware at all.Source [1]
  • The February 2024 update says that, of nearly 70 victims leaked since mid-December 2023, the healthcare sector was the one most commonly victimized.Source [1]

Techniques

Attack vectors

Sources

  1. #StopRansomware: ALPHV Blackcat (AA23-353A) — CISA, 2024-02-27

Last reviewed Oct 2, 2026