Trinetra
Trinetra
Cyber Defense
Home / Threat Intel / Group · ALPHV / BlackCat
Ransomware · Threat Group Dossier Historical activity tracked

ALPHV / BlackCat

ALPHV / BlackCat is a ransomware operation with 731 publicly named victims. Rust-based encryptor, affiliate-driven, Mad-Cat ESXi variant, Emotet/IcedID droppers.

731
Named victims
0
In 2026
59
Countries hit
03 Mar 2024
Last disclosure

fingerprintDossier

Active since
November 2021
Origin / attribution
Former DarkSide / BlackMatter operators
Known aliases
BlackCat, Noberus
Common initial access
Compromised credentials, Microsoft Exchange flaws, SEO poisoning to malware
TTPs & tradecraft
Rust-based encryptor, affiliate-driven, Mad-Cat ESXi variant, Emotet/IcedID droppers.
Notes
Dec 2023 law-enforcement takedown; March 2024 apparent exit scam after Change Healthcare.

publicTop countries hit

United States82
Canada25
Australia21
United Kingdom18
Germany13
Japan11
France11
Brazil11

factoryTop sectors targeted

Business Services19
Healthcare10
Energy7
Manufacturing6
Not Found6
Technology6
Financial3
Government Facilities3

historyRecent named victims

ipmaltamira
MX · Business Services · 03 Mar 2024
Ewig Usa
CN · Manufacturing · 03 Mar 2024
SBM & Co
GB · Not Found · 01 Mar 2024
Petrus Resources Ltd
US · Energy · 01 Mar 2024
Kumagai Gumi Group
JP · Business Services · 01 Mar 2024
Allan Berger & Associates
US · Business Services · 29 Feb 2024
Change Healthcare - Optum - UnitedHealth
US · Healthcare · 28 Feb 2024
verbraucherzentrale hessen
DE · Business Services · 27 Feb 2024
Electro Marteix
ES · Not Found · 27 Feb 2024
Angeles Medical Centers
US · Healthcare · 26 Feb 2024
S+C Partners
CA · Business Services · 26 Feb 2024
Worthen Industries [FULL DATA]
US · Manufacturing · 24 Feb 2024
Family Health center
US · Healthcare · 23 Feb 2024
ANDFLA SRL
RO · Not Found · 23 Feb 2024
Hardeman County Community Health Center
US · Healthcare · 22 Feb 2024

Sourced from open leak-site monitoring · Generated 20 Apr 2026