Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Alphv ransomware

59 victims listed on the Alphv leak site across 14 countries. Most recent disclosure .

Victims
59
0.3% of all tracked
Countries
14
Most: United States
Sectors
8
Most: Business Services
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Alphv and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Alphv, operating a new ransomware family built from scratch in Rust, has targeted 14 countries through attacks on 59 victims.

Who Alphv is

The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote their affiliate program, offering other actors the opportunity to engage in a 'new type of ransomware family' developed from scratch using the Rust programming language. Some clear evidence indicates that the actors behind this new ransomware are not new to cybercrime, and there were links to other affiliate programs such as DarkSide, BlackMatter, and REvil. (After several attacks against large companies, these groups faced pressure and arrests, necessitating the termination of their operations). As a security measure, the operators of ALPHV implemented the requirement for the execution of the ransomware payload by providing an 'access token,' which is supplied by the owners of the Ransomware-as-a-Service to the affiliate. This token is added to the victim's ra

Recorded activity

Disclosures attributed to Alphv in this database run from January 2024 to March 2024, totalling 59 victims — 0.3% of everything tracked here. Alphv has listed victims in 14 countries in this database, most often United States, followed by Canada and Spain. The sectors appearing most in its listings are Business Services, Healthcare, Manufacturing.

How Alphv is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference
External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference
Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference
Scheduled Task/Job T1053 Execution Persistence

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system. Adversaries may use task scheduling to execute programs at system startup or on a scheduled basis for persistence.

Mitigations: Operating System Configuration, User Account Management, Restrict File and Directory Permissions, Privileged Account Management, Audit

MITRE ATT&CK reference
Windows Management Instrumentation T1047 Execution

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management

MITRE ATT&CK reference
Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to Alphv across its recorded activity. They describe the group overall, not any single incident.

YARA detection rules

sekoia.yar
rule ransomware_win_blackcat {
    meta:
        id = "873355f7-3942-4171-9df7-f524bb6b6903"
        description = "Detect the BlackCat ransomware (Windows version)"
        author = "Sekoia.io"
        creation_date = "2022-01-19"
        classification = "TLP:CLEAR"
        version = "1.1"
        
    strings:
        $s1 = "desktop_image::set_desktop_wallpaper=" ascii
        $s2 = "C:\\Users\\Public\\All Usersdeploy_note_and_image_for_all_users=" ascii
        $s3 = "propagate::none" ascii
        $s4 = "propagate::failed=" ascii
        $s5 = "propagate::ok=" ascii
        $s6 = "query_status_process::ok=" ascii
        $s7 = "enum_dependent_services::ok=" ascii
        $s8 = "enum_dependent_services::error=" ascii
        $s9 = "try_stop=" ascii
        $s10 = "try_stop::ok=" ascii
        $s11 = "try_stop::failed=" ascii
        $s12 = "stop=" ascii
        $s13 = "dependent_service_name=" ascii
        $s14 = "kill_all=" ascii
        $s15 = "detach=" ascii
        
    condition:
        uint16(0)==0x5A4D
        and filesize > 2MB and filesize < 4MB
        and all of them
}

Community-contributed rules for Alphv, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Alphv has disclosed 59 victims on its leak site, 0.3% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 14 countries, most often in United States (36 victims), followed by Canada, Spain, Germany.

By industry, its listings concentrate in Business Services, Healthcare, Manufacturing — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Alphv is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Alphv victims 59

Organization Disclosed
Ewig Usa
CNChina
ipmaltamira
MXMexico
Kumagai Gumi Group
JPJapan
Petrus Resources Ltd
USUnited States
SBM & Co
GBUnited Kingdom
Allan Berger & Associates
USUnited States
Change Healthcare - Optum - UnitedHealth
USUnited States
Electro Marteix
ESSpain
verbraucherzentrale hessen
DEGermany
Angeles Medical Centers
USUnited States
S+C Partners
CACanada
Worthen Industries [FULL DATA]
USUnited States
ANDFLA SRL
RORomania
Family Health center
USUnited States
Hardeman County Community Health Center
USUnited States
Worthen Industries [We're giving you one last chance to save your business]
USUnited States
Austen Consultants
USUnited States
KHSS (You have 3 days)
USUnited States
VSP Dental
USUnited States
LoanDepot
USUnited States
Prudential Financial
USUnited States
ASA Electronics [2.7 TB]
USUnited States
Rush Energy Services Inc [Time's up]
CACanada
ArcisGolf
USUnited States
Herrs
USUnited States
New Indy Containerboard
USUnited States
Procopio
USUnited States
The Source
CACanada
Trans-Northern Pipelines
CACanada
Lower Valley Energy, Inc
USUnited States
Rush Energy Services Inc [You have 48 hours]
CACanada
SERCIDE
ESSpain
maddockhenson
USUnited States
Grace Lutheran Foundation
USUnited States
Jewish Home Lifecare
USUnited States
Vail-Summit Orthopaedics & Neurosurgery (VSON)
USUnited States
Hydraflow
USUnited States
LeClair Group
USUnited States
SportsMEDIA Technology
USUnited States
TECHNICA - HACKED AND MORE THEN 300 GB DATA LEAKED!
INIndia
Dutton Brock
CACanada
Draneas Huglin Dooley LLC
USUnited States
Brightstar Care
USUnited States
MBC Law Professional Corporation
CACanada
FULL LEAK! Busse & Busee, PC Attorneys at Law
USUnited States
Herrs (You have 72 hours)
USUnited States
Total Air Solutions
USUnited States
ANS COMPUTER [72hrs]
BEBelgium
Worthen Industries [You have three days]
USUnited States
Busse & Busee, PC Attorneys at Law
USUnited States
Builcore
USUnited States
automotionshade.com
CACanada
R Robertson Insurance Brokers
USUnited States
SHIBLEY RIGHTON
USUnited States
Triella
CACanada
Ursel Phillips Fellows Hopkinson
CACanada
Group Bogart
FRFrance
Erbilbil Bilgisayar
TRTurkey
SAED International
SASaudi Arabia

Frequently asked questions

What is Alphv ransomware?

Alphv is a ransomware threat group that has claimed 59 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Alphv attacked?

Alphv has claimed 59 victims in our database, representing 0.3% of all tracked ransomware attacks. The most targeted countries are United States, Canada, Spain, Germany.

Which countries does Alphv target?

Alphv has attacked organizations in 14 countries. The top targeted countries are: United States, Canada, Spain, Germany.

Which industries does Alphv target?

Alphv most frequently targets the Business Services, Healthcare, Manufacturing sectors based on victim disclosures in our database.

Is Alphv still active?

Alphv's most recent victim disclosure in our database was on March 3, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.