
THREAT‑WATCH
Threat Actors
BlackCat / ALPHV
ALPHV, Noberus
A ransomware-as-a-service operation active from late 2021 that collapsed in an apparent exit scam in March 2024, stealing an affiliate's ransom payment instead of paying out.
BlackCat was known for being written in the Rust programming language, unusual for ransomware at the time, and for aggressive double-extortion tactics. By September 2023, the FBI estimated it had compromised over 1,000 victims and collected close to $300 million in ransom payments, second only to LockBit. After a US law enforcement disruption of its infrastructure in December 2023, the operation exit-scammed in March 2024, taking roughly $22 million meant for an affiliate rather than paying out. The original service has not resumed; many of its estimated 90+ affiliates are believed to have moved to successor operations such as RansomHub and Embargo.
Target Sectors
Healthcare, financial services, and other sectors handling high-value data, targeted opportunistically.