TLP:CLEAR
⚠ ECRIME · RUSSIA / EASTERN-EUROPE-BASED RAAS OPERATION · ASSESSED DARKSIDE/BLACKMATTER LINEAGE
// Threat Actor Profile — Ransomware-as-a-Service (RaaS) Operation / Triple-Extortion Ransomware

BLACKCAT / ALPHV

PROFILE COMPILED: 2026-09-12  |  SOURCES: CISA/FBI/HHS AA23-353A, U.S. DOJ, U.S. Dept. of State (Rewards for Justice), MITRE ATT&CK (S1068), MITRE ATT&CK Evaluations, Mandiant/Google Cloud, CrowdStrike, Microsoft, Flashpoint, Krebs on Security, Picus Security, SentinelOne, 15+ additional vendor/press sources
Status: ORIGINAL GROUP INACTIVE SINCE MAR 2024 (APPARENT EXIT SCAM) — AFFILIATE DIASPORA TO RANSOMHUB / EMBARGO
Threat Level: HIGH (Historical) / RESIDUAL VIA SUCCESSOR RAAS
Primary Motive: Financial Extortion — Triple-Extortion Ransomware
Active Since: November 2021
MITRE ATT&CK: S1068 (Software: BlackCat, aka ALPHV, Noberus) — no Group/G-ID assigned
1,000+
Victims compromised globally as of Sep 2023 (~75% U.S.) — FBI
$300M+
Ransom payments received (of $500M+ demanded) as of Sep 2023 — FBI
$22M
Change Healthcare ransom (Mar 2024) — allegedly withheld from affiliate in exit scam
$10M
U.S. State Dept. reward for information on ALPHV/BlackCat leadership
00
Overview

BlackCat — publicly better known as ALPHV, and tracked in its malware form by MITRE ATT&CK as Noberus (Software S1068) — was, at its peak, the most prolific ransomware-as-a-service operation in the world. Emerging in November 2021 as the first major RaaS family written in Rust, it compromised more than 1,000 organizations worldwide (roughly 75% in the United States), demanded over $500 million in ransom, and collected an estimated $300 million before a coordinated international law-enforcement operation disrupted its infrastructure in December 2023. It is the third documented generation of a single lineage that began with DarkSide: DarkSide's 2021 collapse produced BlackMatter, and BlackMatter's 2021 collapse — corroborated by an April 2022 FBI advisory naming shared developers and money launderers — produced BlackCat/ALPHV (see this repository's companion card: output/actors/2026-09-12_DARKSIDE.html).

BlackCat matters for reasons that go beyond scale. Technically, it was genuinely more capable than its predecessors: a single Rust codebase compiled cleanly across Windows, Linux, and VMware ESXi; a February 2023 "Sphynx" rewrite that embedded legitimate remote-execution tooling (Impacket, RemCom) directly into the payload and reworked its command-line signature specifically to defeat existing detections; and a documented practice, alongside its most capable affiliates, of using malicious signed kernel drivers to forcibly kill endpoint security software before deploying ransomware. Operationally, it attracted — and was, in turn, made devastating by — some of the most capable criminal affiliates in the ecosystem, most notably Scattered Spider (tracked elsewhere as UNC3944/Octo Tempest/0ktapus; see this repository's companion card: output/actors/2026-08-30_SCATTERED-SPIDER.html), whose September 2023 social-engineering intrusions into MGM Resorts and Caesars Entertainment, both deploying BlackCat/ALPHV ransomware, became two of the most closely studied ransomware incidents of the decade.

BlackCat's end was as instructive as its operation. After the FBI's December 2023 disruption — which the group publicly, and accurately, undermined within days by retaining control of its own leak-site signing keys — BlackCat's operators went on to orchestrate what independent researchers assess as a deliberate exit scam: extracting an alleged $22 million ransom from the February 2024 Change Healthcare attack (one of the most disruptive single cyberattacks on U.S. healthcare billing infrastructure in history) and then staging a fake law-enforcement seizure notice to disappear with the funds rather than pay their own affiliate. The group has been inactive since March 2024, but its affiliates did not retire — they are assessed to have substantially migrated to RansomHub and, per infrastructure and code overlap, to Embargo, meaning the operational risk BlackCat represented has not disappeared so much as changed its letterhead once again.

01
Identity & Attribution
Primary NameBlackCat
Sponsor / ParentNone confirmed — independent financially motivated RaaS operation; assessed direct organizational descendant of BlackMatter/DarkSide
Actor TypeRansomware-as-a-Service (RaaS) — core developer group + large affiliate network (~90+ affiliates at peak)
Primary MotivationFinancial — triple-extortion ransomware (encryption + data leak + DDoS threat)
Active SinceNovember 2021
Last ObservedOriginal group inactive since March 2024 (apparent exit scam following the Change Healthcare ransom). No attacks independently attributed to the original operators since.
MITRE G-IDNone assigned — no dedicated Group/intrusion-set page as of 2026-09-12. Tracked as Software S1068 ("BlackCat," associated names ALPHV and Noberus). A full MITRE ATT&CK Evaluations adversary-emulation scenario also exists (see Section 12).
Legal StatusFBI-led international disruption (US, UK, Australia, Germany, Spain, Denmark), Dec 2023, incl. seizure of 900+ leak-site key pairs and a decryptor issued to 500+ victims. U.S. State Dept. Rewards for Justice: $10M for leadership identification, $5M for affiliate arrest/conviction. DOJ indicted/sentenced Americans Ryan Goldberg and Kevin Martin, plus co-conspirator Angelo Martino — former employees of incident-response firms DigitalMint and Sygnia — for deploying ALPHV BlackCat against 5 U.S. companies (Apr–Dec 2023).
Tracking Aliases
BlackCat ALPHV (most common public name) Noberus (MITRE ATT&CK malware name, S1068) ALPHA SPIDER (CrowdStrike) AlphaVM
Attribution Confidence

[HIGH] on Russian-speaking origin and financially motivated, non-state-directed operation — consistent across all vendor reporting and the group's own conduct. [HIGH] on organizational continuity from BlackMatter/DarkSide: this is corroborated independently by an April 2022 FBI advisory naming shared developers and money launderers, by BlackCat operators' own public acknowledgment of the lineage, and by CrowdStrike's ALPHA SPIDER profile — a stronger evidentiary basis than the still-contested DarkSide-to-FIN7/Carbon Spider question documented in the companion DarkSide card. [LOW] on the specific individual identities of BlackCat's core operators: despite a $10M U.S. reward, no core developer has been publicly named, arrested, or indicted as of 2026-09-12 — only affiliates (e.g., the DigitalMint/Sygnia insiders) have faced prosecution.

02
Campaign & Operational Timeline
Nov 2021
Emergence
BlackCat/ALPHV surfaces on Russian-language cybercrime forums as one of the first major RaaS families written in Rust, marketed to affiliates on capability (cross-platform Windows/Linux/ESXi compilation, configurable AES or ChaCha20 encryption) rather than on any professed code of conduct.
2022
Scaling & Vulnerability Exploitation
Affiliates begin shifting from credential-based access toward opportunistic exploitation of known vulnerabilities: Mandiant tracks affiliate UNC4466 exploiting exposed Veritas Backup Exec installations (CVE-2021-27876/-27877/-27878) for initial access. In December 2022, FIN8 (aka Syssphinx) is observed delivering BlackCat via a modified, C-rewritten variant of its Sardonic backdoor — an APT-adjacent group operating as a BlackCat affiliate.
Feb 2023
"Sphynx" 2.0 Rewrite
ALPHV administrators announce the Sphynx update: a reworked build that removes the previous variant's --access-token command-line parameter (specifically to break existing detection signatures) and embeds Impacket and RemCom directly into the payload for lateral movement and remote execution. BlackCat affiliates separately begin exploiting Fortra's GoAnywhere MFT (CVE-2023-0669).
Aug–Sep 2023
Caesars & MGM Resorts Attacks
Scattered Spider, acting as a BlackCat/ALPHV affiliate, breaches Caesars Entertainment in late August via help-desk vishing and Okta/Azure privilege escalation; Caesars reportedly pays roughly $15M of a $30M demand. On September 10, the same affiliate breaches MGM Resorts using an identical vishing technique — a ten-minute phone call to MGM's IT help desk impersonating a LinkedIn-identified employee — but MGM refuses to pay, resulting in a multi-day outage of slot machines, digital room keys, and reservation systems (see companion card: output/actors/2026-08-30_SCATTERED-SPIDER.html).
Sep 2023
FBI Scale Assessment
The FBI reports that ALPHV/BlackCat affiliates have compromised over 1,000 entities globally (~75% U.S.), demanded over $500 million, and received nearly $300 million in ransom payments — establishing BlackCat as the most financially successful ransomware operation tracked to date.
Dec 19, 2023
International Law-Enforcement Disruption
The DOJ and FBI, with the UK, Australia, Germany, Spain, and Denmark, announce a disruption campaign against ALPHV/BlackCat: a confidential source provided access to more than 900 public/private key pairs controlling the group's darknet leak-site infrastructure, enabling the FBI to seize the site and issue a decryption tool to over 500 victims. Within days, ALPHV — having retained a copy of the same keys — "un-seizes" the site and posts a message announcing affiliates are now free to target hospitals and critical infrastructure in retaliation, breaking from earlier DarkSide-lineage norms against such targets.
Feb 2024
Change Healthcare Attack
A BlackCat affiliate exploits CVE-2024-1709 (a trivially exploitable authentication-bypass flaw, CVSS 10.0) and CVE-2024-1708 in ConnectWise ScreenConnect to breach Change Healthcare, a UnitedHealth subsidiary processing a large share of U.S. medical claims and pharmacy transactions. The resulting outage disrupts prescription processing, insurance claims, and billing across the U.S. healthcare system for weeks — one of the most consequential single ransomware incidents on record for the sector.
Mar 2024
Apparent Exit Scam & Collapse
Change Healthcare allegedly pays a $22 million ransom. On March 3, an affiliate using the handle "Notchy" publicly claims on a cybercrime forum that ALPHV/BlackCat operators took the entire payment and withheld the affiliate's contractual cut. Days later, BlackCat's leak site displays a fabricated law-enforcement seizure banner and goes permanently dark — assessed by researchers (Emsisoft and others) as a deliberate exit scam rather than a genuine takedown. The group has been inactive since.
2024–present
Affiliate Diaspora
Displaced BlackCat affiliates are assessed to have substantially migrated to RansomHub, a RaaS brand some analysts assess is partly staffed by former ALPHV insiders, and separately to Embargo, identified as a probable successor based on infrastructure and code overlaps. No core BlackCat developer has surfaced under a new confirmed identity as of this writing.
03
Attack Lifecycle Affiliate-driven intrusion chain over a technically capable shared toolkit

Entry vectors. BlackCat's affiliate base used a wider and more opportunistic range of initial-access techniques than its DarkSide-lineage predecessor. Documented vectors include exploitation of public-facing enterprise software vulnerabilities — Veritas Backup Exec (CVE-2021-27876/-27877/-27878, per Mandiant's UNC4466 tracking), Fortra GoAnywhere MFT (CVE-2023-0669), and, most consequentially, ConnectWise ScreenConnect (CVE-2024-1709/-1708) in the Change Healthcare attack — alongside stolen or IAB-purchased VPN/RDP credentials, and, in the group's most damaging documented intrusions, sophisticated social engineering: Scattered Spider's helpdesk-impersonation vishing calls, which secured full administrative access to MGM Resorts' Okta and Azure environments in a single ten-minute phone call.

Toolchain and internal operations. Once inside, BlackCat affiliates favor a mix of native Windows tooling and a small set of dual-use utilities embedded directly into later payload builds. The February 2023 "Sphynx" rewrite bundled Impacket (for remote service manipulation and lateral movement) and RemCom (a PsExec-style remote command-execution tool) into the ransomware build itself, reducing the affiliate's need to stage separate tooling. Malicious Group Policy Objects, deployed via Windows Task Scheduler, and a sequence of staging batch/PowerShell scripts (publicly documented as start.bat, est.bat, and run.bat) orchestrate credential harvesting from local password stores, network discovery, and eventual payload execution across compromised hosts.

Defense evasion, exfiltration, and impact. Before deploying the ransomware payload, BlackCat-affiliated intrusions are documented using Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques — most notably the POORTRY/STONESTOP malicious signed-driver loader (also associated with Scattered Spider/UNC3944 activity) and separately the commercial "Terminator" tool from the SpyBoy marketplace — to forcibly disable endpoint security agents before encryption begins. Data exfiltration for the group's double/triple-extortion model runs primarily through ExMatter, a purpose-built .NET exfiltration tool. Immediately pre-encryption, the toolkit clears Windows Event Logs (documented via wevtutil.exe el to enumerate available logs, followed by wevtutil.exe cl against each) and deletes Volume Shadow Copies via vssadmin and wmic, disabling Windows automatic repair. The Rust-based payload itself then encrypts the environment — Windows, Linux, and ESXi hosts alike — using a configurable ChaCha20 or AES scheme wrapped in an RSA key-encapsulation layer, before the victim receives a ransom note directing them to a Tor negotiation portal under the threat of encryption, public data leak, and (per the group's own "triple extortion" branding) a DDoS attack against public-facing infrastructure if demands are not met.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; confidence reflects strength and specificity of source documentation
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Veritas Backup Exec (CVE-2021-27876/-27877/-27878), Fortra GoAnywhere MFT (CVE-2023-0669), and ConnectWise ScreenConnect (CVE-2024-1709/-1708, the Change Healthcare vector) all independently confirmed.
Initial Access
T1656
Impersonation
[HIGH] Scattered Spider's helpdesk-vishing impersonation of a real employee secured admin access to MGM's Okta/Azure environment in a single 10-minute call — a confirmed, extensively documented vector.
Initial Access
T1133
External Remote Services
[HIGH] Stolen or IAB-purchased VPN/RDP credentials documented as a recurring initial-access vector across affiliate operations.
Resource Development
T1588.002
Obtain Capabilities: Tool
[HIGH] Core RaaS operators develop the Rust payload and lease it to affiliates for a revenue share; the Sphynx (v2.0) rewrite is a documented deliberate capability update.
Credential Access
T1555
Credentials from Password Stores
[MEDIUM] Documented in the MITRE ATT&CK Evaluations emulation scenario: credentials harvested from a local password store on the initial workstation to pivot to a backup server.
Persistence
T1053.005
Scheduled Task/Job
[MEDIUM] Windows Task Scheduler used to deploy malicious Group Policy Objects across compromised environments (CISA AA23-353A; CloudSEK).
Discovery
T1018
Remote System Discovery
[MEDIUM] Network discovery documented as a standard early-stage step following initial workstation compromise.
Lateral Movement
T1021.002
SMB/Windows Admin Shares
[HIGH] Impacket and RemCom embedded directly into the Sphynx payload for remote service manipulation and command execution (Microsoft).
Defense Evasion
T1562.001
Disable or Modify Tools
[HIGH] BYOVD EDR/AV termination via POORTRY/STONESTOP malicious signed drivers and the commercial "Terminator" (SpyBoy) tool — confirmed across multiple independent vendor reports.
Defense Evasion
T1070.001
Clear Windows Event Logs
[HIGH] Documented sequence: wevtutil.exe el to enumerate logs, then wevtutil.exe cl against each (CISA AA23-353A; Stonefly).
Defense Evasion
T1027
Obfuscated Files or Information
[HIGH] Sphynx rewrite deliberately altered command-line arguments (removing the prior --access-token flag) specifically to defeat existing detection signatures tied to earlier variants.
Impact
T1490
Inhibit System Recovery
[HIGH] Volume Shadow Copy deletion via vssadmin and wmic, and disabling of Windows automatic repair, documented immediately pre-encryption.
Exfiltration
T1567.002
Exfiltration to Cloud Storage
[HIGH] ExMatter, a purpose-built .NET exfiltration tool, documented across the MITRE ATT&CK Evaluations emulation scenario and independent vendor reporting.
Impact
T1486
Data Encrypted for Impact
[HIGH] Rust-based, cross-platform (Windows/Linux/ESXi) payload using configurable ChaCha20 or AES with an RSA key-encapsulation layer (S1068; multiple vendor technical analyses).
Impact
T1657
Financial Theft
[HIGH] Triple-extortion model: encryption, leak-site data-publication threat, and a threatened DDoS attack against public-facing infrastructure if demands go unmet.
05
Targeting Profile
Sector Targeting
Healthcare
PRIMARY
Hospitality / Gaming
HIGH
Professional / Financial Services
HIGH
Manufacturing
MED
Legal Services
MED
Retail
LOW
Geographies~75% U.S.-based victims of the >1,000 compromised globally as of Sep 2023; remainder distributed internationally, corroborated by the multinational composition of the Dec 2023 law-enforcement coalition (UK, Australia, Germany, Spain, Denmark)
Victim ProfileBoth large-scale, high-profile enterprises (MGM Resorts, Caesars Entertainment, Change Healthcare/UnitedHealth) and mid-size opportunistic targets reached via public-facing vulnerability exploitation
Preferred EntryExploitable public-facing backup/MFT/remote-support software; stolen or purchased VPN/RDP credentials; help-desk social-engineering/vishing via elite affiliates
Target DoctrineNo stated exclusion policy (a break from the DarkSide-lineage "no hospitals" norm); explicitly directed affiliates toward hospitals and critical infrastructure in retaliation following the Dec 2023 law-enforcement disruption
06
Tools, Malware & Infrastructure
BlackCat / ALPHV / Noberus Ransomware RaaS Payload · Custom (MITRE S1068)
Rust-based, cross-platform (Windows, Linux, VMware ESXi) ransomware using configurable ChaCha20 or AES encryption wrapped in RSA key encapsulation. The February 2023 "Sphynx" (v2.0) rewrite embeds Impacket and RemCom directly into the payload and reworks command-line arguments — removing the earlier --access-token parameter — specifically to evade detections keyed to prior versions. Weaponized in the MGM Resorts, Caesars Entertainment, and Change Healthcare attacks.
ExMatter .NET Exfiltration Tool · Custom
Purpose-built .NET data-exfiltration tool used to move stolen data to attacker-controlled infrastructure ahead of encryption, underpinning the group's double/triple-extortion leverage. Documented in the MITRE ATT&CK Evaluations emulation scenario as the exfiltration mechanism used after a backup-server compromise.
Sardonic Backdoor (FIN8 variant) C/C++ Backdoor · Third-Party Affiliate Tool
A modified, C-rewritten variant of FIN8's (Syssphinx) Sardonic backdoor, observed in December 2022 delivering BlackCat/Noberus. Supports system-information harvesting, command execution, and a DLL-based plugin system for loading additional payloads; the rewrite deliberately diverges from the original C++ codebase to avoid signature reuse.
POORTRY / STONESTOP Malicious Signed Driver · BYOVD EDR Killer
A malicious kernel-mode driver (POORTRY) loaded via a legitimate but abusable signed driver, paired with a userland loader/controller (STONESTOP), used to forcibly terminate endpoint security agent processes before ransomware deployment. Also documented in Scattered Spider/UNC3944 activity — one of several shared-tooling links between the affiliate and BlackCat's core toolkit.
"Terminator" (SpyBoy) Commercial EDR/AV Killer
A commercially sold security-software-termination tool from the SpyBoy cybercrime marketplace, separately documented as leveraged by BlackCat-affiliated operators to disable AV/EDR protections prior to payload execution.
Impacket / RemCom COTS / Open Source — Embedded in Payload
Legitimate open-source remote-service-manipulation (Impacket) and PsExec-style remote-execution (RemCom) tooling, embedded directly into the Sphynx-era ransomware build for lateral movement and remote command execution (Microsoft).
start.bat / est.bat / run.bat Staging Scripts
Documented batch/PowerShell staging scripts used to orchestrate discrete phases of the intrusion — credential harvesting, GPO deployment, and final payload execution — across compromised hosts.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
NOTENo specific host, network, or file-hash IOC values are reproduced in this card. CISA/FBI/HHS published a dedicated STIX/XML indicator package specific to ALPHV BlackCat (Joint Advisory AA23-353A, updated March 2024); consult that primary source directly for reconstructable indicator values, as this group's infrastructure has fully rotated since its March 2024 collapse and any values transcribed here would carry only archival value.
CVECVE-2021-27876, CVE-2021-27877, CVE-2021-27878 — Veritas Backup Exec (initial-access vector, UNC4466)Mandiant2022
CVECVE-2023-0669 — Fortra GoAnywhere MFT (initial-access vector)Multiple vendors2023
CVECVE-2024-1709 (auth bypass, CVSS 10.0), CVE-2024-1708 (path traversal/RCE, CVSS 8.4) — ConnectWise ScreenConnect (Change Healthcare vector)Unit 42; NVD2024-02
TOOLPOORTRY / STONESTOP malicious signed driver loader (specific driver hash/certificate not independently reproduced here — rotates per campaign)Microsoft; Mandiant2022–2023
08
Analyst Assessment
Overall Threat LevelHIGH (Historical) — original group defunct, residual risk high via affiliate diaspora
Attribution Confidence[HIGH] region/motivation and DarkSide/BlackMatter lineage; [LOW] core-operator identity
TrajectoryOriginal brand extinct since Mar 2024; affiliates (and possibly some core infrastructure/personnel) assessed to persist through RansomHub and Embargo
Most Dangerous CapabilityThe pairing of a technically capable, actively iterated payload (cross-platform Rust, BYOVD EDR killing, signature-evading rewrites) with elite social-engineering affiliates — the combination, not either alone, is what produced incidents at the scale of MGM/Caesars/Change Healthcare
Primary Intel GapNo core-operator identity established despite a $10M reward; whether the Mar 2024 "exit scam" reflects genuine internal collapse or a deliberate strategy to evade the Dec 2023 law-enforcement pressure remains unresolved
Ecosystem / Affiliated Groups
DarkSide (originating lineage — see companion card) BlackMatter (intermediate lineage) Scattered Spider / UNC3944 / Octo Tempest (top-tier affiliate — see companion card) FIN8 / Syssphinx (affiliate, Sardonic backdoor) RansomHub (assessed successor, partial ex-affiliate staffing) Embargo (assessed successor, infra/code overlap)

BlackCat represents the maturation point of the DarkSide-originated RaaS lineage: technically more capable than either predecessor, and — critically — willing to recruit and retain affiliates capable of far more sophisticated intrusions than credential-stuffing or opportunistic vulnerability scanning. The MGM Resorts and Caesars Entertainment attacks are the clearest evidence for this analyst's judgment that BlackCat's core danger was never purely technical: Scattered Spider's ten-minute vishing call succeeded against defenses that would likely have stopped a scripted, low-skill intrusion attempt. Any organization assessing BlackCat-lineage risk should weight identity-verification and help-desk social-engineering resilience at least as heavily as technical patching and EDR deployment — this group's most damaging incidents were won on the phone, not in the code.

The March 2024 collapse leaves a genuinely open analytical question this assessment does not resolve: whether BlackCat's operators executed a purely opportunistic exit scam against one affiliate (Change Healthcare's $22M payment), or whether the entire episode — Change Healthcare, the theft from "Notchy," and the fabricated seizure notice — was a calculated exfiltration of the group's own remaining value ahead of an anticipated second, more damaging law-enforcement action following the December 2023 disruption. The DigitalMint/Sygnia insider-affiliate indictments (incident-response professionals who became ransomware operators against the very type of company they were paid to defend) further complicate the picture of who, precisely, "BlackCat" was by the time of its collapse — the RaaS model's separation of core developers from affiliates means the individuals actually facing prosecution are not necessarily representative of, or even known to, the group's founding operators.

Forward risk trajectory: treat RansomHub and Embargo as the operationally relevant continuation of this threat, not as unrelated new entrants — both inherited meaningful fractions of BlackCat's affiliate base and, in Embargo's case, apparent code/infrastructure lineage. Organizations should expect BlackCat-signature tradecraft (Rust-based cross-platform payloads, BYOVD EDR killing, ScreenConnect/remote-support-software exploitation, and vishing-based help-desk social engineering) to persist under these or future successor brand names, consistent with the pattern already established twice over in this lineage's history.

09
Defensive Recommendations
01
Patch and monitor internet-facing backup, MFT, and remote-support software aggressively. Veritas Backup Exec, Fortra GoAnywhere, and ConnectWise ScreenConnect were all independently exploited as initial-access vectors — treat this software class as high-priority attack surface.
Counters: T1190
02
Harden IT help-desk identity-verification procedures. Require out-of-band or multi-step verification for any password reset or MFA-enrollment request, especially for privileged/admin accounts — the vector that defeated MGM's and Caesars' defenses.
Counters: T1656
03
Enforce MFA and conditional access on identity-provider admin roles. Okta and Azure AD/Entra ID administrative privileges should require hardware-token or equivalent phishing-resistant MFA, not just SMS/push.
Counters: T1133, T1656
04
Deploy Microsoft's vulnerable-driver blocklist / WDAC. Block loading of known-vulnerable signed drivers to prevent BYOVD EDR-killer techniques (POORTRY/STONESTOP and similar) from executing.
Counters: T1562.001
05
Forward Windows Event Logs to a hardened, out-of-band SIEM/log collector. Local log clearing (wevtutil cl) cannot erase logs already shipped off-host, preserving the forensic record even if the endpoint is compromised.
Counters: T1070.001
06
Monitor for Impacket-family tool signatures and RemCom-style remote execution. Both are embedded directly into recent payload builds; network and endpoint detection should not rely solely on the presence of a separate, standalone tool.
Counters: T1021.002
07
Deploy egress monitoring/DLP against known exfiltration tooling. Alert on ExMatter execution patterns and unusual bulk outbound transfer volumes ahead of any encryption event.
Counters: T1567.002
08
Vet and background-check incident-response and security-vendor personnel with privileged access. The DigitalMint/Sygnia indictments demonstrate that trusted third-party IR personnel are a viable, if unusual, insider-affiliate vector for this ecosystem.
Counters: T1486 (via reduced insider-facilitated access)
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
After the FBI seized the group's leak site in December 2023, ALPHV retained a separate copy of the more-than-900 signing key pairs the FBI had obtained and used them to "un-seize" and restore control of the same infrastructure within days — an unusually resilient, apparently pre-planned key-retention posture rather than a from-scratch infrastructure rebuild (DOJ; The Record).
Living-off-the-Land Ratio [MEDIUM]
The Sphynx (v2.0) rewrite embeds legitimate/dual-use tooling (Impacket, RemCom) directly inside the ransomware build itself, blurring the traditional distinction between "custom malware" and "LOLBin abuse" — the payload effectively ships its own living-off-the-land toolkit rather than relying on affiliates to separately stage it (Microsoft).
Anti-Forensics Routines [HIGH]
Documented pre-encryption sequence: enumerate Windows Event Logs via wevtutil.exe el, then clear each one individually with wevtutil.exe cl; delete Volume Shadow Copies via vssadmin and wmic; disable Windows automatic repair — collectively removing both the forensic audit trail and the most common recovery path before the encryption payload runs (CISA AA23-353A; Stonefly).
Tooling Hygiene [HIGH]
The February 2023 Sphynx rewrite deliberately removed the earlier variant's --access-token command-line parameter and introduced a more complex argument structure specifically to defeat detection rules and signatures built against the prior version — a direct, publicly documented example of iterating the payload in response to known defensive countermeasures rather than simply recompiling unchanged code.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
BYOVD EDR/AV Termination — POORTRY/STONESTOP T1562.001
EDR BYPASS
A malicious kernel-mode driver (POORTRY), loaded through abuse of a legitimately signed but exploitable driver-loading mechanism, is controlled by a userland component (STONESTOP) to forcibly terminate the processes of installed endpoint security products before ransomware execution. Documented by Microsoft and Mandiant across multiple BlackCat-affiliated intrusions, and independently associated with Scattered Spider/UNC3944 tradecraft.
Specific driver certificate/hash values and exact STONESTOP command syntax not independently reproduced here (values rotate per campaign and are already stale for detection purposes); consult CISA AA23-353A and Microsoft's published POORTRY/STONESTOP analysis for current indicators.
Commercial EDR/AV Killer — "Terminator" (SpyBoy) T1562.001
EDR BYPASS
A separately sourced, commercially available security-software-termination tool purchased from the SpyBoy cybercrime marketplace, documented as used by BlackCat-affiliated operators as an alternative or supplement to POORTRY/STONESTOP.
Specific version/build details and exact invocation syntax not publicly documented in detail as of 2026-09-12.
Windows Event Log Enumeration & Clearing T1070.001
SIEM EVASION
A two-step sequence removes the forensic audit trail immediately prior to encryption: first enumerate all available Windows Event Logs, then clear each one individually.
wevtutil.exe el wevtutil.exe cl [each log name returned by the prior command]
Command-Line Signature Reworking (Sphynx Rewrite) T1027
EDR BYPASS SIEM EVASION
The February 2023 Sphynx (v2.0) update removed the previously required --access-token command-line parameter used to invoke earlier BlackCat variants and replaced it with a more complex argument set — specifically defeating detection rules and Sigma/EDR signatures written against the older, publicly documented command-line invocation pattern.
Exact post-Sphynx argument syntax not publicly documented in full detail as of 2026-09-12; the pre-Sphynx --access-token <value> pattern is the documented baseline the rewrite was designed to break.
Cross-Platform Rust Compilation for Static-Signature Evasion T1027.002
EDR BYPASS
Rust compilation historically produces binaries with lower coverage under legacy static-signature AV engines than equivalent C/C++ code, and enables the group to compile a single ransomware codebase across Windows, Linux, and VMware ESXi targets from one source tree — widening the range of environments a single payload family can strike.
No further compiler-flag-level specifics are publicly documented as of 2026-09-12.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE ATT&CK EVALUATIONS — ADVERSARY EMULATION SCENARIO ALPHV BlackCat (Managed Services Evaluations 2024)
A precision note on sourcing: MITRE's Center for Threat-Informed Defense (CTID) Adversary Emulation Library (ctid.mitre.org) was searched directly and does not carry a dedicated DarkSide-lineage or BlackCat plan. However, MITRE's related but organizationally distinct ATT&CK Evaluations program (attackevals.mitre-engenuity.org) built and published a full ALPHV BlackCat scenario for its 2024 Managed Services evaluation round, based on real affiliate operations in the wild. The scenario emulates: an Initial Access Broker providing RDP access to a contractor organization; network discovery and password-store credential harvesting on the initial workstation; pivoting to a compromised backup server using harvested administrator credentials; and multi-host data exfiltration via ExMatter. Signature behaviors evaluated include defense evasion, data exfiltration, data encryption, data destruction, and system-recovery-obstruction techniques.
Initial Access (IAB/RDP) Discovery Credential Access Lateral Movement Exfiltration (ExMatter) Data Encryption Data Destruction Recovery Obstruction
Additional Emulation Resources
CISA / FBI / HHS
IOC/TTP advisory + STIX package · Accessed: 2026-09-12
AttackIQ
Purple-team emulation content · Accessed: 2026-09-12
Atomic Red Team / SigmaHQ
No BlackCat/ALPHV-named test or rule identified in the open redcanaryco/atomic-red-team or SigmaHQ/sigma GitHub repositories as of 2026-09-12. Commercial/community content platforms (e.g., SOC Prime) separately publish dedicated ALPHV/BlackCat and "ALPHA SPIDER" detection rule packs compatible with common SIEM/EDR formats.
Gap noted (open-source repos) · Checked: 2026-09-12
13
References URLs are NOT defanged — navigate directly
CISA / FBI / HHS
Accessed: 2026-09-12
MITRE ATT&CK
Accessed: 2026-09-12
MITRE ATT&CK Evaluations
Accessed: 2026-09-12
Krebs on Security
Accessed: 2026-09-12
CrowdStrike
Accessed: 2026-09-12
U.S. Dept. of State
Accessed: 2026-09-12
Wikipedia
Accessed: 2026-09-12
Wikipedia
Accessed: 2026-09-12