Quorum Cyber
ALPHV Ransomware Group Threat Actor Profile
Pages
9
Time to read
8 mins
Publication
Language
English
Pages
9
Time to read
8 mins
Publication
Language
English
This document is a threat actor profile focusing on the ALPHV Ransomware Group, also known as BlackCat, which operates as a Ransomware-as-a-Service (RaaS) entity based in Russia. The profile outlines the group's capabilities, including its support for multiple operating systems such as Windows and Linux, and its unique use of the Rust programming language for ransomware development. The document details the group's operational methods, including the quadruple extortion technique, which involves data deletion, data theft, and threats to third-party suppliers. It also identifies the primary industry sectors targeted by ALPHV, which include finance, healthcare, and technology, and provides an operational timeline of significant attacks attributed to the group. Furthermore, it lists various exploited vulnerabilities and indicators of compromise associated with ALPHV operations. Recommendations for containment and mitigation strategies against ransomware attacks are also included, emphasizing adherence to cybersecurity best practices.