Description
BlackCat (a.k.a. ALPHV) is a ransomware operation written in Rust that emerged in late 2021 with affiliates drawn from the DarkSide and BlackMatter networks. It supports Windows, Linux, and VMware ESXi systems, offers a wide range of configuration options to affiliates, and pioneered features such as a searchable leak site. The operation extorts victims through data theft and encryption, and its developers later ran an exit scheme in which an affiliate seized the decryption keys.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Also known as
ALPHVBlackCatALPHV
MITRE ATT&CK techniques
21 techniques across 7 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.BlackCatALPHV.2 |
| Gen:Variant.Ransom.ALPHV.1 |
| Gen:Variant.Ransom.BlackCat.11 |
| Gen:Variant.Ransom.BlackCat.13 |
| Gen:Variant.Ransom.BlackCat.25 |
| Gen:Variant.Ransom.BlackCat.30 |
| Gen:Variant.Ransom.BlackCat.45 |
| Gen:Variant.Ransom.BlackCat.47 |
| Gen:Variant.Ransom.BlackCat.56 |
| Gen:Variant.Ransom.BlackCat.57 |






