Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

ALPHV/BlackCat

Ransomware 2 detections found

Also known as: ALPHV, BlackCat, Noberus, AlphaV

ALPHV/BlackCat was a Rust-based RaaS operation active from November 2021, notable for double extortion attacks including the February 2024 Change Healthcare breach that disrupted US healthcare billing nationwide. The FBI disrupted its infrastructure in December 2023, and in March 2024 the group staged an apparent exit scam, posting a fake law-enforcement seizure banner and absconding with an approximately $22 million ransom payment without paying its affiliate, after which the group went effectively dormant. Former affiliates and developers are assessed to have dispersed to other RaaS brands (e.g., RansomHub) in subsequent years.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
sigma MaxMpxCt Registry Value Changed test 2024-03-19
sigma DirLister Execution test 2023-02-04