BlackCat
MITRE ATT&CK: S1068 View on attack.mitre.org
Aliases: ALPHV, Noberus, BlackCat
- First seen
- 2021-11-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- linux, windows
- Related IoCs
- 237 (234 malicious)
- Last IoC activity
- 2026-09-01 23:56:54
- Profile updated
- 2026-07-07 12:45:38
Targeted industries: education-and-nonprofits energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing media-and-entertainment professional-services retail-and-hospitality technology-and-telecommunications transportation-and-logistics
Context
BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, BlackCat has been used to target multiple sectors and organizations in various countries and regions in Africa, the Americas, Asia, Australia, and Europe.
Recent IoC activity
234 malicious indicators in Maltiverse are attributed to BlackCat (S1068). The 20 most recently updated:
Detection coverage
- 6 YARA rules
- 416 Sigma rules
Malware & tools used
- Lateral Tool Transfer (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Remote System Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Service Stop (attack-pattern)
- System Information Discovery (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Domain Account (attack-pattern)
- Modify Registry (attack-pattern)
- Domain Groups (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- Windows Permissions (attack-pattern)
- Internal Defacement (attack-pattern)
- Disk Content Wipe (attack-pattern)
- Windows Command Shell (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Access Token Manipulation (attack-pattern)
Used by threat actors
- Scattered Spider (threat-actor)
Detection rules
- TRELLIX_ARC_Ransom_Win_Blackcat (yara-rule)
- ARKBIRD_SOLG_RAN_ALPHV_Dec_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Blackcat (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Blackcat (yara-rule)
- SEKOIA_Ransomware_Win_Blackcat (yara-rule)
- MALPEDIA_Win_Blackcat_Auto (yara-rule)
Reports & references
- computerweekly.com — Alphv Blackcat Ransomware Family Becoming More Dangerous (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
- Microsoft — The Many Lives Of Blackcat Ransomware (report)
- Microsoft — Dev 0832 Vice Society Opportunistic Ransomware Campaigns Impacting Us Education Sector (report)
- CrowdStrike — Anatomy Of Alpha Spider Ransomware (report)
- sentinelone.com — Ransomware Evolution How Cheated Affiliates Are Recycling Victim Data For Profit (report)
- cloud.google.com — Unc3944 Proactive Hardening Recommendations (report)
- CISA — Aa23 320A (report)
- Microsoft — Octo Tempest Crosses Boundaries To Facilitate Extortion Encryption And Destruction (report)
- Broadcom/Symantec — Syssphinx Fin8 Backdoor (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- Microsoft — Re54L7V (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
- Kaspersky — 106824 (report)
- Trend Micro — Datasheet Ransomware In Q1 2022 (report)
- Kaspersky — 106457 (report)
- securityscorecard.com — The Increase In Ransomware Attacks On Local Governments (report)
- intrinsec.com — Alphv Ransomware Gang Analysis (report)
- Trend Micro — Lockbit Conti And Blackcat Lead Pack Amid Rise In Active Raas And Extortion Groups Ransomware In Q1 2022 (report)
- Cisco Talos — From Blackmatter To Blackcat Analyzing (report)
- thehackernews.com — Researchers Connect Blackcat Ransomware (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- medium.com — Blackcat New Rust Based Ransomware Borrowing Blackmatters Configuration 31C8D330A809 (report)