ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

BlackCat Ransomware aka “ALPHV” infections on the rise

Kyle by Kyle
June 16, 2022 - Updated on July 20, 2022
in Malware
Reading Time: 3 mins read
Blackcat ALPHV ransomware
Share on FacebookShare on Twitter

As the ransomware-as-a-service (RaaS) industry grows, more ransomware players come into the mix. BlackCat, also known as ALPHV, is a growing ransomware threat with the ability to target multiple devices and operating systems.

ALPHV is also a unique piece of ransomware malware due to the programming language utilized (Rust). The ransomware can also target devices other than Windows, utilizing multiple points of entry, and has affiliations with multiple big-name threat actors.

ALPHV was first discovered in November 2021, and initially made headlines due to the Rust programming language it was written in. Due to the malware authors writing the ransomware in a more modern language, the payload can evade detection with ease. It also may prevent some security solutions from analyzing and parsing the ransomware’s binary due to this new programming language. Microsoft has witnessed successful attacks infecting both Windows and Linux devices and even VMWare instances.

ALPHV Threat actors leveraging Microsoft Exchange server vulnerabilities

Microsoft is now reporting that the ALPHV ransomware is utilizing Microsoft Exchange vulnerabilities to exploit unpatched servers.

In one instance, Microsoft’s security team has observed the threat actor(s) laterally move through a victim’s network, stealing data, and credentials that were used for double extortion (threatening to release data if the ransom is not paid).

Two weeks following the compromise of the unpatched Exchange server, the adversary deployed the AlPHV payload to machines on the network utilizing Microsoft’s tool, PsExec.

“While the common entry vectors for these threat actors include remote desktop applications and compromised credentials, we also saw a threat actor leverage Exchange server vulnerabilities to gain target network access,” stated the Microsoft 365 Defender Threat Intelligence Team.

Microsoft did not mention the Exchange vulnerabilities utilized in the attacks, but they linked to a security advisory from March 2021.

Microsoft also did not name the ransomware threat actors, but in a case study, they stated multiple cybercrime groups are utilizing this RaaS actively in the wild.

ALPHV Entry Microsoft Exchange
ALPHV entry via the Microsoft Exchange vulnerability, source Microsoft

Cybercriminals are switching to ALPHV/BlackCat

A collective of cybercriminals being tracked under the callsign FIN12, known for deploying malware such as Conti, Hive, and Ryuk ransomware which mainly targeted the healthcare sector.

We’ve observed that this group added BlackCat to their list of distributed payloads beginning March 2022,” Microsoft explained.

“Their switch to BlackCat from their last used payload (Hive) is suspected to be due to the public discourse around the latter’s decryption methodologies.”

The ALPHV ransomware is also being deployed by another group tracked under the name DEV-0504. This group normally exfiltrates data from their victims utilizing the malware Stealbit, which is provided by the “LockBit gang” as a part of their RaaS services.

DEV-0504 uses other ransomware such as BlackMatter (December 2021), Ryuk, Revil, Conti, and LockBit 2.0.

Microsoft suggests all organizations review their identity posture, update all vulnerable Microsoft Exchange servers, and monitor any outside access to their networks.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The threat grows

This past April the FBI released a flash alert warning of the new ransomware threat. They had observed the networks of over 60 organizations worldwide get encrypted by the new threat between November 2021 and March 2022.

“Many of the developers and money launderers for BlackCat/ALPHV are linked to Darkside/Blackmatter, indicating they have extensive networks and experience with ransomware operations,” the FBI indicated.

The real number of ALPHV victims is more than likely a lot higher than what had been observed by the threat analysis team. More than 480 samples have been submitted to the ID-Ransomware platform between November 2021 and June 2022.

BlackCat Ransomware activity
BlackCat/ALPHV ransomware activity. Source, ID-Ransomware

In the FBI’s April alert, they asked IT admins and security teams that run into ALPHV/BlackCat activity within their networks to gather and report any information they have to their local FBI Cyber unit.

Some helpful information to crack down on these threat actors include “IP logs showing callbacks from foreign IP addresses, Bitcoin or Monero addresses and transaction IDs, communications with the threat actors, the decryptor file, and/or a benign sample of an encrypted file.”

For more information on ransomware, and how you can defend yourself, check out our other news reports, here.

Source: Microsoft's Security Blog
Tags: ALPHVBlackCatmicrosoftransomware
Previous Post

$6 million Rewarded by Aurora Labs to Hacker who saved 70,000 ETH

Next Post

Are Bluetooth signals being used to track smartphones?

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.