Ransomware
ALPHV/BlackCat
Ransomware
2 detections found
Also known as: ALPHV, BlackCat, Noberus, AlphaV
ALPHV/BlackCat was a Rust-based RaaS operation active from November 2021, notable for double extortion attacks including the February 2024 Change Healthcare breach that disrupted US healthcare billing nationwide. The FBI disrupted its infrastructure in December 2023, and in March 2024 the group staged an apparent exit scam, posting a fake law-enforcement seizure banner and absconding with an approximately $22 million ransom payment without paying its affiliate, after which the group went effectively dormant. Former affiliates and developers are assessed to have dispersed to other RaaS brands (e.g., RansomHub) in subsequent years.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- #StopRansomware: ALPHV Blackcat — CISA/FBI/HHS
- BlackCat, Software S1068 — MITRE ATT&CK
- BlackCat ransomware shuts down in exit scam, blames the "feds" — BleepingComputer
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| sigma | MaxMpxCt Registry Value Changed | test | 2024-03-19 |
| sigma | DirLister Execution | test | 2023-02-04 |