BlackCat
MITRE G1048Also known as Blackcat/AlphV, ALPHV, BlackCat/ALPHV, ALPHV/BlackCat
Reports
11
First seen
Sep 14, 2023
Last seen
Jul 10, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×7×7
United States×7
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×10T1567 Exfiltration Over Web Service ×4T1078 Valid Accounts ×3T1562.001 Impair Defenses: Disable or Modify Tools ×3T1021 Remote Services ×3T1190 Exploit Public-Facing Application ×2T1490 Inhibit System Recovery ×2T1021.002 Remote Services: SMB/Windows Admin Shares ×2T1657 Financial Theft ×2T1566 Phishing ×2T1195 Supply Chain Compromise ×2T1570 Lateral Tool Transfer ×2
Indicators
filename ×17domain ×2cve ×2url ×1hash_sha256 ×1ip_v4 ×1registry_key ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High