BlackCat

Threat Actor updated 22 days ago (2024-11-29T14:31:51.968Z)
Download STIX
Preview STIX
BlackCat, also known as Alphv, is a Russian-based ransomware-as-a-service group that has recently targeted organizations in the healthcare and academic sectors. Lehigh Valley Health Network (LVHN), which operates 13 hospitals and numerous physician practices and clinics in eastern Pennsylvania, reported being hit with an attack by BlackCat. NextGen Health and PharmaCare Services were among the alleged recent victims listed on BlackCat's leak data site. BlackCat's tooling is constantly changing as they cycle through testing/usage, updating their arsenal frequently. The group demanded a ransom payment from LVHN, but the organization refused to pay. BlackCat has threatened to publish stolen data from Reddit servers if their demands are not met. The group claims to have successfully breached Reddit servers on February 5, 2023, and exfiltrated a total of 80GB of zipped data. In response to BlackCat's demands, Reddit withdrew its API pricing changes, while refusing to pay the $4.5 million ransom demanded by the group. BlackCat's current tactics seem to involve making the most of the current media attention on Reddit and using it to their advantage.
Description last updated: 2023-06-27T10:24:44.723Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Alphv is a possible alias for BlackCat. Alphv, also known as BlackCat, is a threat actor group that has been linked to numerous cyberattacks, particularly targeting the healthcare sector. The group made headlines when it stole 5TB of data from Morrison Community Hospital, causing significant disruption and raising concerns about patient p
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Extortion
Ransom
Windows
Encryption
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the BlackCat Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
2 years ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
SecurityIntelligence.com
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
BankInfoSecurity
2 years ago
Malwarebytes
2 years ago
BankInfoSecurity
2 years ago
Securityaffairs
2 years ago
CERT-EU
2 years ago
CSO Online
2 years ago
DARKReading
2 years ago
CERT-EU
2 years ago