news.mlab.sh
Threat intelligence
Threat actor

ALPHV

Profile from actors.mlab.sh, coverage from our own index.

First seen
2021-01-01 00:00:00
Motivation
Financial gain
TLP
WHITE

(Palo Alto) BlackCat (aka ALPHV) is a ransomware family that surfaced in mid-November 2021 and quickly gained notoriety for its sophistication and innovation. Operating a ransomware-as-a-service (RaaS) business model, BlackCat was observed soliciting for affiliates in known cybercrime forums, offering to allow affiliates to leverage the ransomware and keep 80-90% of the ransom payment. The remainder would be paid to the BlackCat author. The threat actors leveraging BlackCat, often referred to as the 'BlackCat gang,' utilize numerous tactics that are becoming increasingly commonplace in the ransomware space. Notably, they use multiple extortion techniques in some cases, including the siphoning of victim data before ransomware deployment, threats to release data if the ransom is not paid and distributed denial-of-service (DDoS) attacks. Known affiliates are: 1. Subgroup: Scattered Spider

Also known as

ALPHVALPHVMAmbitious ScorpiusBlackCat GangUNC4466

Coverage 10

ransomware

What the ransom note won’t say

This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i…

WeLiveSecurity · Apr 20, 2026 High