Threat actor
ALPHV Blackcat
Also known as BlackCatSource [1]
FBI, CISA and HHS describe ALPHV Blackcat as a ransomware-as-a-service operation whose affiliates have experience with ransomware and data extortion.Source [1]
What authorities and investigators report
- The advisory says affiliates posed as company IT or help-desk staff and used phone calls or SMS messages to obtain credentials from employees.Source [1]
- It says affiliates used the open-source adversary-in-the-middle framework Evilginx2 to obtain MFA credentials, login credentials and session cookies.Source [1]
- It says affiliates moved or exfiltrated victim data before deploying the ransomware, and that some affiliates extorted victims without deploying ransomware at all.Source [1]
- The February 2024 update says that, of nearly 70 victims leaked since mid-December 2023, the healthcare sector was the one most commonly victimized.Source [1]
Techniques
Attack vectors
Sources
- #StopRansomware: ALPHV Blackcat (AA23-353A) — CISA, 2024-02-27
Last reviewed Oct 2, 2026