HackerFeeds
All ransomware groups

alphv

731 tracked victims
·first seen 2021-09-09·last activity 2024-03-03

Group profile

The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote their affiliate program, offering other actors the opportunity to engage in a 'new type of ransomware family' developed from scratch using the Rust programming language.<BR> <BR> Some clear evidence indicates that the actors behind this new ransomware are not new to cybercrime, and there were links to other affiliate programs such as DarkSide, BlackMatter, and REvil. (After several attacks against large companies, these groups faced pressure and arrests, necessitating the termination of their operations).<BR> <BR> As a security measure, the operators of ALPHV implemented the requirement for the execution of the ransomware payload by providing an 'access token,' which is supplied by the owners of the Ransomware-as-a-Service to the affiliate. This token is added to the victim's ransom note so that they can contact the threat actor responsible for encrypting the data.<BR> <BR> ALPHV affiliates employ double and triple extortion techniques, meaning the publication of the company's name on leak sites, threats of data leakage, and lastly, threats of DDoS attacks against the organization.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    In some attacks, threat actors utilized ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

  • T1133External Remote Services

    As an initial attack vector, insecure RDP and VPNs were exploited.

  • T1190Exploit Public-Facing Application

    BlackCat affiliates may purchase access to victims' network infrastructure on underground forums.

TA0002

Execution

  • T1053Scheduled Task/Job

    When deploying ransomware on the victim's network infrastructure, BlackCat affiliates may leverage group policies, resulting in the creation of a scheduled task (on each host) initiating the ransomware.

  • T1059.001Command and Scripting Interpreter: PowerShell

    To disrupt IIS, delete volume shadow copies, disable recovery, clear Windows event logs, etc., BlackCat ransomware utilizes command shell to execute appropriate commands.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    LockBit affiliates use batch scripts to execute malicious commands.

  • T1072Windows Management Instrumentation

    Adversaries may use wmic to gather information and execute various commands, including deleting volume shadow copies. They may also use Impacket's wmiexec module to execute commands and move laterally across the network.

  • T1106Native API

    BlackCat uses native API.

  • T1569.002System Services: Service Execution

    BlackCat Ransomware for Windows can self-propagate on the local network using legitimate PsExec utility (contained within its body), which creates a temporary system service.

TA0003

Persistence

  • T1078Valid Accounts

    Legitimate accounts obtained by adversaries may be used to ensure persistence in the compromised infrastructure.

  • T1547Server Software Component

    Successful exploitation of ProxyShell vulnerabilities allowed adversaries to place a web shell on a vulnerable Microsoft Exchange server.

TA0004

Privilege Escalation

  • T1078Valid Accounts

    To escalate privileges, BlackCat may use stolen legitimate accounts specified in configuration data.

  • T1134.002Access Token Manipulation: Create Process with Token

    To escalate privileges, BlackCat ransomware may initiate its process using stolen authentication data and the CreateProcessWithLogonW function.

  • T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control

    To bypass UAC, BlackCat ransomware may elevate privileges using the ICMLuaUtil COM interface, as well as utilize the Masquerade PEB method.

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    BlackCat ransomware uses obfuscation.

  • T1036Masquerading

    Adversaries use a renamed SoftPerfect Network Scanner executable to svchost.exe.

  • T1070.001Indicator Removal: Clear Windows Event Logs

    Using wevtutil, BlackCat can clear all Windows event logs on a compromised host.

  • T1112Modify Registry

    To propagate, BlackCat uses PsExec to modify the MaxMpxCt system registry parameter to increase the number of failed network requests for each client.

  • T1140Deobfuscate/Decode Files or Information

    BlackCat decrypts configuration data, as well as decrypts and unpacks legitimate PsExec utility and an additional BAT file contained within the ransomware body.

  • T1497Virtualization/Sandbox Evasion

    For anti-analysis (including in a sandbox), ALPHV MORPH checks the access token value of the command line parameter. Its value must contain the correct first 16 characters used to decrypt BlackCat's configuration data.

  • T1562.001Impair Defenses: Disable or Modify Tools

    To avoid detection, adversaries terminate processes and services related to security software and antivirus.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Adversaries may dump the LSASS process to obtain authentication data using legitimate tools (procdump, comsvcs.dll).

  • T1552Unsecured Credentials

    Adversaries may use NirSoft utilities to obtain authentication data from registry and file.

  • T1555Credentials from Password Stores

    Adversaries may use NirSoft utilities to extract authentication data from web browsers and other storage spaces.

TA0010

Exfiltration

  • T1020Automated Exfiltration

    After access is obtained, files from target hosts are automatically uploaded to the legitimate cloud storage service MEGA using the Rclone utility.

  • T1030Data Transfer Size Limits

    To avoid exceeding data size limits and triggering security controls, stolen data may be sent in fixed-size blocks.

  • T1041Exfiltration Over C2 Channel

    When using Cobalt Strike, attackers can send collected information through the Cobalt Strike server communication channels.

  • T1048.002Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

    Attackers may use the ExMatter exfiltration tool, which sends stolen data to specified SFTP and WebDav resources in the ExMatter configuration.

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Attackers use the Rclone sync utility to upload stolen data to the legitimate cloud storage service MEGA.

TA0040

Impact

  • T1485Data Destruction

    If credentials to access a victim's chat leak, BlackCat affiliates can delete encryption keys, rendering file decryption impossible.

  • T1486Data Encrypted for Impact

    BlackCat encrypts the content of files on the local system as well as on available network resources.

  • T1489Service Stop

    BlackCat stops security, backup, database, email, and other specified services in the configuration.

  • T1490Inhibit System Recovery

    BlackCat deletes Windows volume shadow copies using vssadmin and wmic, disables recovery in the Windows boot menu using bccedit, and empties the Recycle Bin. BlackCat can stop backup services and destroy virtual machine snapshots.

  • T1498Network Denial of Service

    If the victim refuses to pay the ransom, BlackCat may conduct DDoS attacks against the victim's infrastructure.

Recent victims

showing 50 of 731
DateWebsite / victimSectorCountry
2024-03-03Business ServicesMX
2024-03-03ManufacturingCN
2024-03-01Business ServicesGB
2024-03-01
petrusresources.com
Petrus Resources Ltdpetrusresources.com
EnergyUS
2024-03-01
kumagaigumi.co.jp
Kumagai Gumi Groupkumagaigumi.co.jp
Business ServicesJP
2024-02-29
bergerlawnola.com
Allan Berger & Associatesbergerlawnola.com
Business ServicesUS
2024-02-28
changehealthcare.com
Change Healthcare - Optum - UnitedHealthchangehealthcare.com
HealthcareUS
2024-02-27
verbraucherzentrale-hessen.de
verbraucherzentrale hessenverbraucherzentrale-hessen.de
Business ServicesDE
2024-02-27
emtek.es
Electro Marteixemtek.es
ManufacturingES
2024-02-26
angelesmentalhealth.com
Angeles Medical Centersangelesmentalhealth.com
HealthcareUS
2024-02-26
scpllp.com
S+C Partnersscpllp.com
Business ServicesCA
2024-02-24
worthenind.com
Worthen Industries [FULL DATA]worthenind.com
ManufacturingUS
2024-02-23
fhckzoo.com
Family Health centerfhckzoo.com
HealthcareUS
2024-02-23
andfla.ro
ANDFLA SRLandfla.ro/
Agriculture and Food ProductionRO
2024-02-22
hardemanhealth.org
Hardeman County Community Health Centerhardemanhealth.org/
HealthcareUS
2024-02-22
worthenind.com
Worthen Industries [We're giving you one last chance to save your business]worthenind.com
ManufacturingUS
2024-02-21
khss.com
KHSS (You have 3 days)khss.com
TechnologyUS
2024-02-21
austein-it.com
Austen ConsultantsAustein-it.com
Business ServicesUS
2024-02-18
vspdental.com
VSP Dentalvspdental.com
HealthcareUS
2024-02-16
prudential.com
Prudential Financialprudential.com
Financial ServicesUS
2024-02-16Financial ServicesUS
2024-02-12
rushenergyservices.com
Rush Energy Services Inc [Time's up]rushenergyservices.com
EnergyCA
2024-02-15
asaelectronics.com
ASA Electronics [2.7 TB]asaelectronics.com
TechnologyUS
2024-02-13
thesource.ca
The Sourcethesource.ca/
Business ServicesCA
2024-02-13Hospitality and TourismUS
2024-02-13
tnpi.ca
Trans-Northern Pipelinestnpi.ca/
EnergyCA
2024-02-13Agriculture and Food ProductionUS
2024-02-13Business ServicesUS
2024-02-13
newindycontainerboard.com
New Indy Containerboardnewindycontainerboard.com
ManufacturingUS
2024-02-12
rushenergyservices.com
Rush Energy Services Inc [You have 48 hours]rushenergyservices.com
EnergyCA
2024-02-12EnergyES
2024-02-12
lvenergy.com
Lower Valley Energy, Inclvenergy.com
EnergyUS
2024-02-10
maddockhenson.com
maddockhensonmaddockhenson.com
Business ServicesUS
2024-02-09
graceluthfound.com
Grace Lutheran Foundationgraceluthfound.com
HealthcareUS
2024-02-08
jewishhome.org
Jewish Home Lifecarejewishhome.org
HealthcareUS
2024-02-05
vsortho.com
Vail-Summit Orthopaedics & Neurosurgery (VSON)vsortho.com
HealthcareUS
2024-01-31
smt.com
SportsMEDIA Technologysmt.com
TechnologyUS
2023-12-13
leclairgroup.com
LeClair Groupleclairgroup.com
HealthcareUS
2024-01-31ManufacturingUS
2024-01-30
technicacorp.com
TECHNICA - HACKED AND MORE THEN 300 GB DATA LEAKED!technicacorp.com
TechnologyIN
2024-01-29
duttonbrock.com
Dutton Brockduttonbrock.com
Business ServicesCA
2024-01-26
draneaslaw.com
Draneas Huglin Dooley LLCdraneaslaw.com
Business ServicesUS
2024-01-24
brightstarcare.com
Brightstar Carebrightstarcare.com
HealthcareUS
2024-01-24
mbclaw.ca
MBC Law Professional Corporationmbclaw.ca/
Business ServicesCA
2024-01-19
bussepc.com
FULL LEAK! Busse & Busee, PC Attorneys at Lawbussepc.com
Business ServicesUS
2024-01-23
totalairfl.com
Total Air Solutionstotalairfl.com
Business ServicesUS
2024-01-23
herrs.com
Herrs (You have 72 hours)herrs.com
Agriculture and Food ProductionUS
2024-01-22
anscomputer.be
ANS COMPUTER [72hrs]anscomputer.be
TechnologyBE
2024-01-20
worthenind.com
Worthen Industries [You have three days]worthenind.com
ManufacturingUS
2024-01-19
bussepc.com
Busse & Busee, PC Attorneys at Lawbussepc.com
Business ServicesUS