🚀 Introducing the CloudSEK MCP Server!
Read more
BlackCat, known as ALPHV or Noberus, was a Russian-speaking ransomware-as-a-service (RaaS) operation that ran from November 2021 until it collapsed in an exit scam in March 2024. It earned its place in ransomware history as the first major family written in Rust and as one of the most prolific extortion groups of its era. By September 2023, the FBI estimated it had compromised more than 1,000 victims and collected close to $300 million in ransom payments, second only to LockBit.
The group is now defunct, but its tools, tactics, and affiliates did not disappear. Many of those affiliates moved to successor operations such as RansomHub, and BlackCat's methods remain a template that newer crews still follow. This guide explains what BlackCat was, how its attacks worked, the major incidents it caused, the law-enforcement takedown that disrupted it, and the exit scam that ended it.
BlackCat was a ransomware-as-a-service operation, meaning its core developers built and maintained the malware while recruited affiliates carried out the actual intrusions in exchange for a share of each ransom. The operation went by several names: its developers called it ALPHV, security researchers named it BlackCat after the black-cat icon on its leak site, and some vendors referred to it as Noberus.
The group first surfaced in mid-November 2021 and was widely assessed to be a rebrand of the earlier DarkSide and BlackMatter operations, with further ties to REvil affiliates. CloudSEK's Threat Intelligence team profiled the group in its first weeks, tracking its dark-web leak site, its recruitment of affiliates on Russian-speaking cybercrime forums, and its stated intent to encrypt Windows, Linux, and VMware ESXi systems.Â
From the outset, BlackCat positioned itself as a professional, well-resourced operation rather than an opportunistic one. Within the wider ransomware economy, BlackCat ranked among the most active RaaS brands of 2022 and 2023, alongside LockBit and Cl0p.
Several features set BlackCat apart from the dozens of ransomware families active at the time and explain why it grew so quickly.

BlackCat was the first professional ransomware family built in Rust, a modern programming language that compiles to fast, cross-platform code. Rust let the operators maintain a single codebase that ran on Windows, Linux, and ESXi, and its compiled output was harder for some security tools to analyze than the C and C++ binaries those tools were tuned for. This technical choice gave BlackCat both reach and a degree of evasion that older families lacked.
Most RaaS operations of the period paid affiliates roughly 70 percent of each ransom. BlackCat offered 80 to 90 percent, a deliberately generous split designed to attract skilled intrusion specialists away from rival programs.
CloudSEK's researchers observed recruitment posts in December 2021 advertising exactly that rate, along with a preference for affiliates experienced with Windows, Linux, and ESXi environments. The high payout doubled as advertising, since affiliates spread word of the favorable terms among their peers.
BlackCat pioneered a triple-extortion model. Beyond encrypting a victim's files, affiliates stole sensitive data before encryption and threatened to publish it on a public leak site, and they added the threat of a distributed denial-of-service (DDoS) attack against victims who refused to pay. Layering three forms of pressure made the operation harder to ignore than encryption alone, particularly for organizations that held regulated or reputationally sensitive data.
Because it was built in Rust, BlackCat could encrypt Windows servers and workstations, Linux hosts, and VMware ESXi virtualization environments from the same toolkit. ESXi targeting was especially damaging, since a single encrypted hypervisor could take down many virtual machines at once.
In February 2023, the operators released an upgraded variant, marketed as Sphynx or BlackCat 2.0, that added stronger defense evasion and extra tooling for affiliates.
A BlackCat intrusion followed a recognizable kill chain. Because affiliates operated independently, the exact tools varied, but the stages below describe the typical flow from first access to extortion.

Affiliates gained entry mainly through stolen or purchased credentials, exposed remote desktop services, phishing, and the exploitation of unpatched vulnerabilities in internet-facing systems. Some campaigns used malicious advertising that disguised the payload as legitimate software downloads. A recurring pattern was access through trusted third parties, where a smaller, less-defended supplier provided a quiet route into a larger target.
Once inside, the ransomware escalated privileges and dismantled the host's defenses. CloudSEK's technical analysis documented how the binary bypassed User Account Control through the CMSTPLUA COM interface to gain administrative rights, then disabled security services and recovery options.
It deleted Volume Shadow Copies using vssadmin and wmic, disabled automatic repair, and attempted to clear event logs, removing the backups and forensic traces a victim would otherwise rely on. The malware ran from the command line and required a 32-byte access token to decrypt its embedded configuration, an anti-analysis measure that stopped automated sandboxes from running it.
With elevated access, affiliates spread across the network using tools such as PsExec and targeted Active Directory to reach more systems. Before triggering encryption, they exfiltrated the most sensitive data they could find, often using a custom exfiltration tool called ExMatter, and in some campaigns deployed a utility named Eamfo to steal credentials held by Veeam backup software. This stolen data became the leverage for the second stage of extortion, independent of whether the victim could restore files from backup.
BlackCat then encrypted files using AES, with the AES key itself protected by an RSA public key carried in the configuration. To lock large environments quickly, it supported several encryption modes, including intermittent encryption that scrambled only portions of each file, selected through a smart-pattern or percentage option that traded completeness for speed.
It appended a random extension to encrypted files and dropped a ransom note, typically named in the form RECOVER-[random]-FILES.txt, in every affected directory. As a file-encrypting crypto ransomware, it set the ransom note as the desktop wallpaper and, in virtualized environments, shut down and encrypted ESXi virtual machines and removed their snapshots to prevent easy recovery.
With files locked and data stolen, the affiliate delivered its demands. The ransom note pointed victims to a unique Tor site that displayed proof of the exfiltrated data and the payment terms, denominated in cryptocurrency. Victims who refused to pay saw their data published on BlackCat's public leak site, and some faced the additional threat of a DDoS attack. This naming-and-shaming approach increased pressure and advertised the group's activity to other criminals.
BlackCat affiliates struck organizations across construction, energy, healthcare, retail, technology, and the public sector. A handful of high-profile incidents defined its reputation.
The September 2023 attacks on MGM and Caesars were carried out by an affiliate known as Scattered Spider, which combined BlackCat's ransomware with social-engineering of IT help desks. The Change Healthcare attack five months later proved to be both the group's most consequential strike and the trigger for its downfall.
The rise and fall of BlackCat unfolded over roughly two and a half years.
In December 2023, an international operation led by the FBI disrupted BlackCat's infrastructure. According to the Department of Justice, investigators gained access to the group's systems with the help of a confidential source who had access to its affiliate panel, then seized several of its websites. Over the preceding 18 months, the FBI had quietly developed a decryption tool and used it to help more than 500 victims restore their systems without paying, sparing them from ransom demands totaling around $68 million. Law enforcement partners in the United Kingdom, Denmark, Germany, Spain, Australia, and elsewhere took part, with Europol coordinating.
The disruption was not a clean kill. BlackCat's administrators briefly reclaimed their domain, claimed the FBI had seized only an old server, and openly encouraged affiliates to retaliate by targeting hospitals and critical infrastructure. In the months that followed, the healthcare sector became the group's most frequently listed victim category.
The true end came through greed rather than enforcement. After affiliates breached Change Healthcare in February 2024 and a $22 million ransom was paid, BlackCat's operators kept the entire sum instead of sharing it with the affiliate who carried out the attack. Around March 1, 2024, they shut down their servers, and a few days later, posted a fake FBI seizure notice on their leak site, the first time a ransomware group had faked its own takedown. Europol, the DOJ, and the UK's National Crime Agency all denied involvement, confirming that the notice was a cover for a classic exit scam.
No. BlackCat has been inactive since March 2024, when its operators ran the exit scam, shut down their infrastructure, and disappeared with the Change Healthcare ransom. No attacks have been attributed to the original group since. Analysts assess that many of its affiliates moved to RansomHub, which emerged in February 2024, while others later joined Cicada3301. The US State Department's reward of up to $10 million for information on BlackCat's leaders remains open.
The joint advisory from CISA, the FBI, and HHS catalogs the tactics, techniques, and procedures BlackCat affiliates used, mapped to the MITRE ATT&CK framework. The table below summarizes the most consistent behaviors.
The behavioral artifacts below recurred across BlackCat intrusions and support detection rules.
The full, current list of file hashes and network indicators lives in the CISA advisory and the FBI FLASH releases, which security teams use to build detection rules.
BlackCat is gone, but its successors reuse the same playbook, so the defenses that countered it still apply to the RaaS groups that replaced it.
Most BlackCat intrusions began with a stolen credential or an unpatched, internet-facing system, so prevention starts there. Enforcing phishing-resistant multi-factor authentication on all remote access closes the most common entry point, and monitoring for leaked credentials catches exposed logins before an affiliate buys them. Prompt patching of internet-facing services removes the vulnerabilities that affiliates exploit, while network segmentation limits how far an intruder can move after gaining a foothold.Â
Endpoint detection and response can flag the privilege escalation and shadow-copy deletion that preceded encryption, and security-awareness training reduces successful phishing. Maintaining offline, immutable backups is the single control that most reliably blunts an encryption attack.
An organization that detects an active BlackCat-style attack isolates affected systems immediately to halt lateral movement and encryption, then preserves logs and forensic evidence before rebuilding. Recovery runs from clean, offline backups rather than from any decryptor an attacker offers. Because law enforcement released a working decryptor for some BlackCat variants, victims of that specific family can check with the FBI or CISA before assuming files are unrecoverable.Â
Reporting the incident to national authorities is both a legal consideration in many jurisdictions and a practical one, since it can unlock recovery assistance. Paying a ransom carries no guarantee of recovery and, in the BlackCat case, sometimes funded an operation that planned to vanish regardless.
Ransomware operations like BlackCat organize on dark-web forums and announce victims on leak sites long before and long after they reach any single target. Watching that activity gives defenders early warning of which groups are active and which sectors they are hitting.
CloudSEK Threat Intelligence tracks ransomware groups, their affiliates, and their leak-site activity across the surface, deep, and dark web, so a security team can see when a group names its organization or exposes its data, and act before the damage spreads. That visibility complements, rather than replaces, the endpoint, patching, and backup controls that stop an attack in progress.
Nothing. There are two names for the same ransomware operation. The developers called it ALPHV; researchers named it BlackCat after the black-cat icon on its leak site. Noberus is a third name some vendors use.
A Russian-speaking cybercrime group widely assessed to be a rebrand of the DarkSide and BlackMatter operations, with ties to REvil affiliates. No individual operators have been publicly named, and the US State Department offers up to $10 million for information on its leaders.
By September 2023, the FBI estimated BlackCat had compromised more than 1,000 victims and collected close to $300 million in ransoms, making it the second most prolific ransomware-as-a-service operation after LockBit.
Sometimes. In December 2023, the FBI released a decryption tool that helped over 500 victims recover without paying. It does not work for every variant, so affected organizations can check with the FBI or CISA before assuming files are lost.
No. RansomHub is a separate ransomware-as-a-service group that emerged in February 2024. Analysts assess that many former BlackCat affiliates joined it after BlackCat shut down, but the operations and operators are distinct.
Rust lets one codebase target Windows, Linux, and VMware ESXi, and its compiled output was harder for some security tools to analyze. That cross-platform reach and evasion is why BlackCat became the first major ransomware family built in Rust.
