alphv
Group profile
The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote their affiliate program, offering other actors the opportunity to engage in a 'new type of ransomware family' developed from scratch using the Rust programming language.<BR> <BR> Some clear evidence indicates that the actors behind this new ransomware are not new to cybercrime, and there were links to other affiliate programs such as DarkSide, BlackMatter, and REvil. (After several attacks against large companies, these groups faced pressure and arrests, necessitating the termination of their operations).<BR> <BR> As a security measure, the operators of ALPHV implemented the requirement for the execution of the ransomware payload by providing an 'access token,' which is supplied by the owners of the Ransomware-as-a-Service to the affiliate. This token is added to the victim's ransom note so that they can contact the threat actor responsible for encrypting the data.<BR> <BR> ALPHV affiliates employ double and triple extortion techniques, meaning the publication of the company's name on leak sites, threats of data leakage, and lastly, threats of DDoS attacks against the organization.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
In some attacks, threat actors utilized ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
T1133External Remote Services
As an initial attack vector, insecure RDP and VPNs were exploited.
T1190Exploit Public-Facing Application
BlackCat affiliates may purchase access to victims' network infrastructure on underground forums.
Execution
T1053Scheduled Task/Job
When deploying ransomware on the victim's network infrastructure, BlackCat affiliates may leverage group policies, resulting in the creation of a scheduled task (on each host) initiating the ransomware.
T1059.001Command and Scripting Interpreter: PowerShell
To disrupt IIS, delete volume shadow copies, disable recovery, clear Windows event logs, etc., BlackCat ransomware utilizes command shell to execute appropriate commands.
T1059.003Command and Scripting Interpreter: Windows Command Shell
LockBit affiliates use batch scripts to execute malicious commands.
T1072Windows Management Instrumentation
Adversaries may use wmic to gather information and execute various commands, including deleting volume shadow copies. They may also use Impacket's wmiexec module to execute commands and move laterally across the network.
T1106Native API
BlackCat uses native API.
T1569.002System Services: Service Execution
BlackCat Ransomware for Windows can self-propagate on the local network using legitimate PsExec utility (contained within its body), which creates a temporary system service.
Persistence
Privilege Escalation
T1078Valid Accounts
To escalate privileges, BlackCat may use stolen legitimate accounts specified in configuration data.
T1134.002Access Token Manipulation: Create Process with Token
To escalate privileges, BlackCat ransomware may initiate its process using stolen authentication data and the CreateProcessWithLogonW function.
T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control
To bypass UAC, BlackCat ransomware may elevate privileges using the ICMLuaUtil COM interface, as well as utilize the Masquerade PEB method.
Defense Evasion
T1027Obfuscated Files or Information
BlackCat ransomware uses obfuscation.
T1036Masquerading
Adversaries use a renamed SoftPerfect Network Scanner executable to svchost.exe.
T1070.001Indicator Removal: Clear Windows Event Logs
Using wevtutil, BlackCat can clear all Windows event logs on a compromised host.
T1112Modify Registry
To propagate, BlackCat uses PsExec to modify the MaxMpxCt system registry parameter to increase the number of failed network requests for each client.
T1140Deobfuscate/Decode Files or Information
BlackCat decrypts configuration data, as well as decrypts and unpacks legitimate PsExec utility and an additional BAT file contained within the ransomware body.
T1497Virtualization/Sandbox Evasion
For anti-analysis (including in a sandbox), ALPHV MORPH checks the access token value of the command line parameter. Its value must contain the correct first 16 characters used to decrypt BlackCat's configuration data.
T1562.001Impair Defenses: Disable or Modify Tools
To avoid detection, adversaries terminate processes and services related to security software and antivirus.
Credential Access
T1003.001OS Credential Dumping: LSASS Memory
Adversaries may dump the LSASS process to obtain authentication data using legitimate tools (procdump, comsvcs.dll).
T1552Unsecured Credentials
Adversaries may use NirSoft utilities to obtain authentication data from registry and file.
T1555Credentials from Password Stores
Adversaries may use NirSoft utilities to extract authentication data from web browsers and other storage spaces.
Exfiltration
T1020Automated Exfiltration
After access is obtained, files from target hosts are automatically uploaded to the legitimate cloud storage service MEGA using the Rclone utility.
T1030Data Transfer Size Limits
To avoid exceeding data size limits and triggering security controls, stolen data may be sent in fixed-size blocks.
T1041Exfiltration Over C2 Channel
When using Cobalt Strike, attackers can send collected information through the Cobalt Strike server communication channels.
T1048.002Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Attackers may use the ExMatter exfiltration tool, which sends stolen data to specified SFTP and WebDav resources in the ExMatter configuration.
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
Attackers use the Rclone sync utility to upload stolen data to the legitimate cloud storage service MEGA.
Impact
T1485Data Destruction
If credentials to access a victim's chat leak, BlackCat affiliates can delete encryption keys, rendering file decryption impossible.
T1486Data Encrypted for Impact
BlackCat encrypts the content of files on the local system as well as on available network resources.
T1489Service Stop
BlackCat stops security, backup, database, email, and other specified services in the configuration.
T1490Inhibit System Recovery
BlackCat deletes Windows volume shadow copies using vssadmin and wmic, disables recovery in the Windows boot menu using bccedit, and empties the Recycle Bin. BlackCat can stop backup services and destroy virtual machine snapshots.
T1498Network Denial of Service
If the victim refuses to pay the ransom, BlackCat may conduct DDoS attacks against the victim's infrastructure.
Recent victims
showing 50 of 731| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2024-03-03 | ipmaltamiraipmaltamira.com.mx | Business Services | MX |
| 2024-03-03 | Ewig Usaewig-mco.com | Manufacturing | CN |
| 2024-03-01 | SBM & Cosbmaccountancy.co.uk/ | Business Services | GB |
| 2024-03-01 | Petrus Resources Ltdpetrusresources.com | Energy | US |
| 2024-03-01 | Kumagai Gumi Groupkumagaigumi.co.jp | Business Services | JP |
| 2024-02-29 | Allan Berger & Associatesbergerlawnola.com | Business Services | US |
| 2024-02-28 | Change Healthcare - Optum - UnitedHealthchangehealthcare.com | Healthcare | US |
| 2024-02-27 | verbraucherzentrale hessenverbraucherzentrale-hessen.de | Business Services | DE |
| 2024-02-27 | Electro Marteixemtek.es | Manufacturing | ES |
| 2024-02-26 | Angeles Medical Centersangelesmentalhealth.com | Healthcare | US |
| 2024-02-26 | S+C Partnersscpllp.com | Business Services | CA |
| 2024-02-24 | Worthen Industries [FULL DATA]worthenind.com | Manufacturing | US |
| 2024-02-23 | Family Health centerfhckzoo.com | Healthcare | US |
| 2024-02-23 | ANDFLA SRLandfla.ro/ | Agriculture and Food Production | RO |
| 2024-02-22 | Hardeman County Community Health Centerhardemanhealth.org/ | Healthcare | US |
| 2024-02-22 | Worthen Industries [We're giving you one last chance to save your business]worthenind.com | Manufacturing | US |
| 2024-02-21 | KHSS (You have 3 days)khss.com | Technology | US |
| 2024-02-21 | Austen ConsultantsAustein-it.com | Business Services | US |
| 2024-02-18 | VSP Dentalvspdental.com | Healthcare | US |
| 2024-02-16 | Prudential Financialprudential.com | Financial Services | US |
| 2024-02-16 | LoanDepotloandepot.com | Financial Services | US |
| 2024-02-12 | Rush Energy Services Inc [Time's up]rushenergyservices.com | Energy | CA |
| 2024-02-15 | ASA Electronics [2.7 TB]asaelectronics.com | Technology | US |
| 2024-02-13 | The Sourcethesource.ca/ | Business Services | CA |
| 2024-02-13 | ArcisGolfarcisgolf.com | Hospitality and Tourism | US |
| 2024-02-13 | Trans-Northern Pipelinestnpi.ca/ | Energy | CA |
| 2024-02-13 | Herrsherrs.com | Agriculture and Food Production | US |
| 2024-02-13 | Procopioprocopio.com | Business Services | US |
| 2024-02-13 | New Indy Containerboardnewindycontainerboard.com | Manufacturing | US |
| 2024-02-12 | Rush Energy Services Inc [You have 48 hours]rushenergyservices.com | Energy | CA |
| 2024-02-12 | SERCIDEsercide.com | Energy | ES |
| 2024-02-12 | Lower Valley Energy, Inclvenergy.com | Energy | US |
| 2024-02-10 | maddockhensonmaddockhenson.com | Business Services | US |
| 2024-02-09 | Grace Lutheran Foundationgraceluthfound.com | Healthcare | US |
| 2024-02-08 | Jewish Home Lifecarejewishhome.org | Healthcare | US |
| 2024-02-05 | Vail-Summit Orthopaedics & Neurosurgery (VSON)vsortho.com | Healthcare | US |
| 2024-01-31 | SportsMEDIA Technologysmt.com | Technology | US |
| 2023-12-13 | LeClair Groupleclairgroup.com | Healthcare | US |
| 2024-01-31 | Hydraflow www.hydraflow.com | Manufacturing | US |
| 2024-01-30 | TECHNICA - HACKED AND MORE THEN 300 GB DATA LEAKED!technicacorp.com | Technology | IN |
| 2024-01-29 | Dutton Brockduttonbrock.com | Business Services | CA |
| 2024-01-26 | Draneas Huglin Dooley LLCdraneaslaw.com | Business Services | US |
| 2024-01-24 | Brightstar Carebrightstarcare.com | Healthcare | US |
| 2024-01-24 | MBC Law Professional Corporationmbclaw.ca/ | Business Services | CA |
| 2024-01-19 | FULL LEAK! Busse & Busee, PC Attorneys at Lawbussepc.com | Business Services | US |
| 2024-01-23 | Total Air Solutionstotalairfl.com | Business Services | US |
| 2024-01-23 | Herrs (You have 72 hours)herrs.com | Agriculture and Food Production | US |
| 2024-01-22 | ANS COMPUTER [72hrs]anscomputer.be | Technology | BE |
| 2024-01-20 | Worthen Industries [You have three days]worthenind.com | Manufacturing | US |
| 2024-01-19 | Busse & Busee, PC Attorneys at Lawbussepc.com | Business Services | US |

