◇ SIGN IN
← all actors
ransomware

ALPHV / BlackCat

defunctmedium confidence
Ransomware
ALPHVBlackCatNoberus
Attribution
RaaS (Russian-speaking, unattributed to a state)
Origin
Unknown (Russian-speaking operators assessed)
First seen
2021
Last active
2024 (exit scam)
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Egypt, Saudi Arabia
Sectors
Energy/petroleum, engineering, government

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Egypt, Saudi Arabia (Energy/petroleum, engineering, government sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

ALPHV/BlackCat was a sophisticated Rust-based ransomware-as-a-service operation, notable as one of the first major Rust ransomware families, that collapsed in an apparent exit scam in early 2024.

History

First observed in November 2021, ALPHV/BlackCat was written in Rust and offered via an affiliate RaaS model, targeting organizations across the Americas, Europe, Africa, Asia and Australia. It ran a searchable leak site, pioneered triple-extortion pressure tactics, and drew a joint CISA/FBI advisory (AA23-353A) in December 2023.

In early 2024, after the extortion of Change Healthcare, the operation abruptly shut down in what researchers widely assess was an exit scam: affiliates were reportedly denied payment while leadership disappeared with funds and a fake law-enforcement 'seizure' banner was posted. The reputational damage ended the brand's ability to attract affiliates. Displaced affiliates are widely assessed to have migrated to successor operations such as RansomHub, and researchers have discussed Embargo as a possible rebrand based on infrastructure overlaps.

During its active period, ALPHV/BlackCat listed victims in Egypt and Saudi Arabia, among many other countries, on its leak site. These listings were extortion claims and should be treated as unverified allegations unless confirmed by the affected organization or a reputable authority.

Notable campaigns

2024
Change Healthcare extortion
A BlackCat affiliate breached Change Healthcare; a disputed multimillion-dollar payment preceded the operation's collapse.
2024
Exit scam / shutdown
The operation went dark in an apparent exit scam, posting a fake seizure notice and abandoning affiliates.
2023
MENA leak-site listings
Egyptian and Saudi organizations were listed on the ALPHV leak site (claimed, not independently confirmed).

Claimed victims · 731 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
Banco SolAOFinancial Services
PRESTIGE MAINTENANCE USA WAS HACKEDUSProfessional Services
Hometrust Mortgage CompanyUSFinancial Services
Rob Levine & Associates LawyersUSProfessional Services
Insurance Agency Marketing ServicesUSFinancial Services
ipmaltamiraMXProfessional Services
Ewig UsaCNManufacturing
SBM & CoGBProfessional Services
Petrus Resources LtdUSEnergy & Utilities
Kumagai Gumi GroupJPProfessional Services
Allan Berger & AssociatesUSProfessional Services
Electro MarteixESManufacturing