White Paper
THREAT PROFILE: Alphv Ransomware
ALPHV, also known as BlackCat, is a ransomware-as-a-service (RaaS) operation first identified in 2021 that uses a double-extortion model to maximize pressure on victims. The group encrypts systems while simultaneously stealing sensitive data and threatening to publish it through a data leak site if ransom demands are not met. Operating through an affiliate-based business model, ALPHV offers generous revenue-sharing arrangements that have helped it attract cybercriminal partners and expand its reach. This threat profile examines the group’s targeted industries and regions, known exploited vulnerabilities, associated threat actors, attack tools, and behaviors across both Windows and Linux environments. The report also maps ALPHV’s tactics, techniques, and procedures to the MITRE ATT&CK frame
