BlackCat (ALPHV) Ransomware: Attacks, Timeline & Status

BlackCat (ALPHV) ransomware was a Rust-based RaaS behind the Change Healthcare attack. Learn how it worked, its major attacks, the FBI takedown, and its 2024 shutdown.
Published on
Friday, August 21, 2026
Updated on
August 21, 2026

BlackCat, known as ALPHV or Noberus, was a Russian-speaking ransomware-as-a-service (RaaS) operation that ran from November 2021 until it collapsed in an exit scam in March 2024. It earned its place in ransomware history as the first major family written in Rust and as one of the most prolific extortion groups of its era. By September 2023, the FBI estimated it had compromised more than 1,000 victims and collected close to $300 million in ransom payments, second only to LockBit.

The group is now defunct, but its tools, tactics, and affiliates did not disappear. Many of those affiliates moved to successor operations such as RansomHub, and BlackCat's methods remain a template that newer crews still follow. This guide explains what BlackCat was, how its attacks worked, the major incidents it caused, the law-enforcement takedown that disrupted it, and the exit scam that ended it.

What is BlackCat (ALPHV) Ransomware?

BlackCat was a ransomware-as-a-service operation, meaning its core developers built and maintained the malware while recruited affiliates carried out the actual intrusions in exchange for a share of each ransom. The operation went by several names: its developers called it ALPHV, security researchers named it BlackCat after the black-cat icon on its leak site, and some vendors referred to it as Noberus.

The group first surfaced in mid-November 2021 and was widely assessed to be a rebrand of the earlier DarkSide and BlackMatter operations, with further ties to REvil affiliates. CloudSEK's Threat Intelligence team profiled the group in its first weeks, tracking its dark-web leak site, its recruitment of affiliates on Russian-speaking cybercrime forums, and its stated intent to encrypt Windows, Linux, and VMware ESXi systems. 

From the outset, BlackCat positioned itself as a professional, well-resourced operation rather than an opportunistic one. Within the wider ransomware economy, BlackCat ranked among the most active RaaS brands of 2022 and 2023, alongside LockBit and Cl0p.

Why BlackCat Was Notable

Several features set BlackCat apart from the dozens of ransomware families active at the time and explain why it grew so quickly.

blackcat ransomware features

The First Major Ransomware Written in Rust

BlackCat was the first professional ransomware family built in Rust, a modern programming language that compiles to fast, cross-platform code. Rust let the operators maintain a single codebase that ran on Windows, Linux, and ESXi, and its compiled output was harder for some security tools to analyze than the C and C++ binaries those tools were tuned for. This technical choice gave BlackCat both reach and a degree of evasion that older families lacked.

A Lucrative Affiliate Model

Most RaaS operations of the period paid affiliates roughly 70 percent of each ransom. BlackCat offered 80 to 90 percent, a deliberately generous split designed to attract skilled intrusion specialists away from rival programs.

CloudSEK's researchers observed recruitment posts in December 2021 advertising exactly that rate, along with a preference for affiliates experienced with Windows, Linux, and ESXi environments. The high payout doubled as advertising, since affiliates spread word of the favorable terms among their peers.

Triple Extortion

BlackCat pioneered a triple-extortion model. Beyond encrypting a victim's files, affiliates stole sensitive data before encryption and threatened to publish it on a public leak site, and they added the threat of a distributed denial-of-service (DDoS) attack against victims who refused to pay. Layering three forms of pressure made the operation harder to ignore than encryption alone, particularly for organizations that held regulated or reputationally sensitive data.

Cross-Platform Reach

Because it was built in Rust, BlackCat could encrypt Windows servers and workstations, Linux hosts, and VMware ESXi virtualization environments from the same toolkit. ESXi targeting was especially damaging, since a single encrypted hypervisor could take down many virtual machines at once.

In February 2023, the operators released an upgraded variant, marketed as Sphynx or BlackCat 2.0, that added stronger defense evasion and extra tooling for affiliates.

How a BlackCat Ransomware Attack Worked

A BlackCat intrusion followed a recognizable kill chain. Because affiliates operated independently, the exact tools varied, but the stages below describe the typical flow from first access to extortion.

blackcat ransomware attack flow

1. Initial Access

Affiliates gained entry mainly through stolen or purchased credentials, exposed remote desktop services, phishing, and the exploitation of unpatched vulnerabilities in internet-facing systems. Some campaigns used malicious advertising that disguised the payload as legitimate software downloads. A recurring pattern was access through trusted third parties, where a smaller, less-defended supplier provided a quiet route into a larger target.

2. Privilege Escalation and Defense Evasion

Once inside, the ransomware escalated privileges and dismantled the host's defenses. CloudSEK's technical analysis documented how the binary bypassed User Account Control through the CMSTPLUA COM interface to gain administrative rights, then disabled security services and recovery options.

It deleted Volume Shadow Copies using vssadmin and wmic, disabled automatic repair, and attempted to clear event logs, removing the backups and forensic traces a victim would otherwise rely on. The malware ran from the command line and required a 32-byte access token to decrypt its embedded configuration, an anti-analysis measure that stopped automated sandboxes from running it.

3. Lateral Movement and Data Exfiltration

With elevated access, affiliates spread across the network using tools such as PsExec and targeted Active Directory to reach more systems. Before triggering encryption, they exfiltrated the most sensitive data they could find, often using a custom exfiltration tool called ExMatter, and in some campaigns deployed a utility named Eamfo to steal credentials held by Veeam backup software. This stolen data became the leverage for the second stage of extortion, independent of whether the victim could restore files from backup.

4. Encryption

BlackCat then encrypted files using AES, with the AES key itself protected by an RSA public key carried in the configuration. To lock large environments quickly, it supported several encryption modes, including intermittent encryption that scrambled only portions of each file, selected through a smart-pattern or percentage option that traded completeness for speed.

It appended a random extension to encrypted files and dropped a ransom note, typically named in the form RECOVER-[random]-FILES.txt, in every affected directory. As a file-encrypting crypto ransomware, it set the ransom note as the desktop wallpaper and, in virtualized environments, shut down and encrypted ESXi virtual machines and removed their snapshots to prevent easy recovery.

5. Extortion

With files locked and data stolen, the affiliate delivered its demands. The ransom note pointed victims to a unique Tor site that displayed proof of the exfiltrated data and the payment terms, denominated in cryptocurrency. Victims who refused to pay saw their data published on BlackCat's public leak site, and some faced the additional threat of a DDoS attack. This naming-and-shaming approach increased pressure and advertised the group's activity to other criminals.

Notable BlackCat Ransomware Attacks

BlackCat affiliates struck organizations across construction, energy, healthcare, retail, technology, and the public sector. A handful of high-profile incidents defined its reputation.

Organization When Impact
MGM Resorts September 2023 Operations across hotels and casinos were disrupted; MGM declined to pay and reported an estimated $100 million impact.
Caesars Entertainment September 2023 Attacked in the same period by the same affiliate, Caesars reportedly paid roughly $15 million.
Change Healthcare (UnitedHealth/Optum) February 2024 A $22 million ransom was paid; data on more than 100 million people was exposed, the largest US healthcare breach on record.
Florida court system 2023 A breach of court infrastructure disrupted judicial operations and exposed sensitive case data.

The September 2023 attacks on MGM and Caesars were carried out by an affiliate known as Scattered Spider, which combined BlackCat's ransomware with social-engineering of IT help desks. The Change Healthcare attack five months later proved to be both the group's most consequential strike and the trigger for its downfall.

BlackCat Ransomware Timeline

The rise and fall of BlackCat unfolded over roughly two and a half years.

Timeline Event
November 2021 BlackCat/ALPHV first observed; the RaaS recruits affiliates on Russian-speaking forums.
April 2022 The FBI issues a FLASH advisory after the group compromises around 60 victims.
February 2023 The Sphynx (BlackCat 2.0) update adds stronger defense evasion and tooling.
September 2023 MGM and Caesars are hit; the FBI later reports 1,000+ victims and roughly $300 million collected.
December 2023 An FBI-led operation seizes the leak site and shares a decryptor with 500+ victims.
February 2024 Affiliates breach Change Healthcare; a $22 million ransom is paid.
March 2024 BlackCat fakes a law-enforcement seizure notice, keeps the ransom, and shuts down.
2024 onward Former affiliates migrate to RansomHub and, later, Cicada3301.

The FBI Takedown and BlackCat's Shutdown

In December 2023, an international operation led by the FBI disrupted BlackCat's infrastructure. According to the Department of Justice, investigators gained access to the group's systems with the help of a confidential source who had access to its affiliate panel, then seized several of its websites. Over the preceding 18 months, the FBI had quietly developed a decryption tool and used it to help more than 500 victims restore their systems without paying, sparing them from ransom demands totaling around $68 million. Law enforcement partners in the United Kingdom, Denmark, Germany, Spain, Australia, and elsewhere took part, with Europol coordinating.

The disruption was not a clean kill. BlackCat's administrators briefly reclaimed their domain, claimed the FBI had seized only an old server, and openly encouraged affiliates to retaliate by targeting hospitals and critical infrastructure. In the months that followed, the healthcare sector became the group's most frequently listed victim category.

The true end came through greed rather than enforcement. After affiliates breached Change Healthcare in February 2024 and a $22 million ransom was paid, BlackCat's operators kept the entire sum instead of sharing it with the affiliate who carried out the attack. Around March 1, 2024, they shut down their servers, and a few days later, posted a fake FBI seizure notice on their leak site, the first time a ransomware group had faked its own takedown. Europol, the DOJ, and the UK's National Crime Agency all denied involvement, confirming that the notice was a cover for a classic exit scam.

Is BlackCat Ransomware Still Active?

No. BlackCat has been inactive since March 2024, when its operators ran the exit scam, shut down their infrastructure, and disappeared with the Change Healthcare ransom. No attacks have been attributed to the original group since. Analysts assess that many of its affiliates moved to RansomHub, which emerged in February 2024, while others later joined Cicada3301. The US State Department's reward of up to $10 million for information on BlackCat's leaders remains open.

BlackCat TTPs and Indicators of Compromise

The joint advisory from CISA, the FBI, and HHS catalogs the tactics, techniques, and procedures BlackCat affiliates used, mapped to the MITRE ATT&CK framework. The table below summarizes the most consistent behaviors.

MITRE ATT&CK Tactic Technique Used by BlackCat
Initial Access Valid accounts, exploitation of public-facing applications, and phishing for entry.
Execution Command-line execution requiring an access token to decrypt the configuration.
Privilege Escalation User Account Control bypass via the CMSTPLUA COM interface.
Defense Evasion Disabling security services, deleting Volume Shadow Copies, and clearing logs.
Credential Access Harvesting stored and cached credentials for reuse across the network.
Lateral Movement PsExec and remote services to spread to additional hosts.
Exfiltration Theft of sensitive data to a dedicated tool before encryption.
Impact AES file encryption, ESXi virtual-machine encryption, and inhibited recovery.

Key Indicators of Compromise

The behavioral artifacts below recurred across BlackCat intrusions and support detection rules.

Indicator Value or Pattern
Ransom Note RECOVER-[random]-FILES.txt, dropped in every encrypted directory
Encrypted File Extension A random string unique to each campaign (example: .uhwuvzu)
Checkpoint Files checkpoints-[filename].[extension], created during encryption
Named Pipe \\.\pipe\__rust_anonymous_pipe1__.[PID].[random]
Shadow Copy Deletion vssadmin.exe Delete Shadows /all /quiet and wmic.exe Shadowcopy Delete
Recovery Disabled bcdedit /set {default} recoveryenabled No
Registry Modification LanmanServer\Parameters\MaxMpxCt set to 65535

The full, current list of file hashes and network indicators lives in the CISA advisory and the FBI FLASH releases, which security teams use to build detection rules.

How to Defend Against and Recover From BlackCat-Style Attacks

BlackCat is gone, but its successors reuse the same playbook, so the defenses that countered it still apply to the RaaS groups that replaced it.

Prevention

Most BlackCat intrusions began with a stolen credential or an unpatched, internet-facing system, so prevention starts there. Enforcing phishing-resistant multi-factor authentication on all remote access closes the most common entry point, and monitoring for leaked credentials catches exposed logins before an affiliate buys them. Prompt patching of internet-facing services removes the vulnerabilities that affiliates exploit, while network segmentation limits how far an intruder can move after gaining a foothold. 

Endpoint detection and response can flag the privilege escalation and shadow-copy deletion that preceded encryption, and security-awareness training reduces successful phishing. Maintaining offline, immutable backups is the single control that most reliably blunts an encryption attack.

Response and Recovery

An organization that detects an active BlackCat-style attack isolates affected systems immediately to halt lateral movement and encryption, then preserves logs and forensic evidence before rebuilding. Recovery runs from clean, offline backups rather than from any decryptor an attacker offers. Because law enforcement released a working decryptor for some BlackCat variants, victims of that specific family can check with the FBI or CISA before assuming files are unrecoverable. 

Reporting the incident to national authorities is both a legal consideration in many jurisdictions and a practical one, since it can unlock recovery assistance. Paying a ransom carries no guarantee of recovery and, in the BlackCat case, sometimes funded an operation that planned to vanish regardless.

Tracking Ransomware Groups With Threat Intelligence

Ransomware operations like BlackCat organize on dark-web forums and announce victims on leak sites long before and long after they reach any single target. Watching that activity gives defenders early warning of which groups are active and which sectors they are hitting.

CloudSEK Threat Intelligence tracks ransomware groups, their affiliates, and their leak-site activity across the surface, deep, and dark web, so a security team can see when a group names its organization or exposes its data, and act before the damage spreads. That visibility complements, rather than replaces, the endpoint, patching, and backup controls that stop an attack in progress.

Frequently Asked Questions

What is the difference between ALPHV and BlackCat?

Nothing. There are two names for the same ransomware operation. The developers called it ALPHV; researchers named it BlackCat after the black-cat icon on its leak site. Noberus is a third name some vendors use.

Who created BlackCat ransomware?

A Russian-speaking cybercrime group widely assessed to be a rebrand of the DarkSide and BlackMatter operations, with ties to REvil affiliates. No individual operators have been publicly named, and the US State Department offers up to $10 million for information on its leaders.

How much money did BlackCat ransomware make?

By September 2023, the FBI estimated BlackCat had compromised more than 1,000 victims and collected close to $300 million in ransoms, making it the second most prolific ransomware-as-a-service operation after LockBit.

Can files encrypted by BlackCat be decrypted?

Sometimes. In December 2023, the FBI released a decryption tool that helped over 500 victims recover without paying. It does not work for every variant, so affected organizations can check with the FBI or CISA before assuming files are lost.

Is RansomHub the same as BlackCat?

No. RansomHub is a separate ransomware-as-a-service group that emerged in February 2024. Analysts assess that many former BlackCat affiliates joined it after BlackCat shut down, but the operations and operators are distinct.

Why was BlackCat written in Rust?

Rust lets one codebase target Windows, Linux, and VMware ESXi, and its compiled output was harder for some security tools to analyze. That cross-platform reach and evasion is why BlackCat became the first major ransomware family built in Rust.

Related Posts
Brand Impersonation: Types, Examples, and How to Stop It
Brand impersonation uses a company's name, logo, or domain to defraud its customers. Learn the types, real examples, and how to detect, prevent, and take it down.
ClearFake: What it is, How it Works, and Defense
ClearFake is a malware campaign that hijacks legitimate websites with fake browser updates and CAPTCHA lures to deliver infostealers. Learn how ClearFake works and how to stop it.
Mirai Botnet: How It Works, Attacks, and Protection
The Mirai botnet infects IoT devices via default credentials to launch massive DDoS attacks. Learn how Mirai works, its famous attacks, variants, and how to defend IoT devices against it.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.