Ransomware Group intelligence
Alphv
InactiveTrack Alphv with 731 published victims and 6 known leak locations in a single intelligence view.
Overview
Alphv is tracked by Breach House as a ransomware group with 731 published victims.
United States is currently the most targeted country in this dataset.
6 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (6)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion |
| Leak location 2 | Onion service | Down checked 2h ago | alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion |
| Leak location 4 | Onion service | Down checked 2h ago | vqifktlreqpudvulhbzmc5gocbeawl67uvs2pttswemdorbnhaddohyd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | basemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad.onion |
| Leak location 5 | Onion service | Down checked 2h ago | alphvuzxyxv6ylumd2ngp46xzq3pw6zflomrghvxeuks6kklberrbmyd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | 2cuqgeerjdba2rhdiviezodpu3lc4qz2sjf4qin6f7std2evleqlzjid.onion |
Top Activity Sectors (17)
- Communication / Marketing 154
- Services 95
- Not identified 95
- Finance / Legal / Insurance 87
- Healthcare / Pharma 55
- Manufacturing / Engineering 35
- Public Sector 32
- Construction / Real Estate 32
- Energy 31
- IT 30
- Education 21
- Retail / E-commerce 18
- Telecommunications 14
- Agriculture / Food 11
- Hospitality / Food & Beverage / Tourism 10
- Transportation / Travel / Logistics 9
- NGOs / Associations 2
Typical Attacks (21)
▼How Alphv typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via BlackCat.
-
T1047 Windows Management Instrumentation Execution
What they do: BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.003 Windows Command Shell Execution
What they do: BlackCat can execute commands on a compromised network with the use of `cmd.exe`.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: BlackCat has the ability modify access tokens.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: BlackCat can bypass UAC to escalate privileges.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1222.001 Windows Permissions Defense Impairment
What they do: BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: BlackCat can clear Windows event logs using `wevtutil.exe`.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1018 Remote System Discovery Discovery
What they do: BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: BlackCat can utilize `net use` commands to discover the user name on a compromised host.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1069.002 Domain Groups Discovery
What they do: BlackCat can determine if a user on a compromised host has domain admin privileges.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: BlackCat can obtain the computer name and UUID.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: BlackCat can enumerate files for encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.002 Domain Account Discovery
What they do: BlackCat can utilize `net use` commands to identify domain users.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: BlackCat has the ability to discover network shares on compromised networks.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1680 Local Storage Discovery Discovery
What they do: BlackCat can enumerate local drives.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: BlackCat can replicate itself across connected servers via `psexec`.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1486 Data Encrypted for Impact Impact
What they do: BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: BlackCat has the ability to stop VM services on compromised networks.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: BlackCat can change the desktop wallpaper on compromised hosts.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1561.001 Disk Content Wipe Impact
What they do: BlackCat has the ability to wipe VM snapshots on compromised networks.
What that means: Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
Tools Observed (32)
▼Software Alphv has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
alphv3.txt
>> Introduction
Important files on your system was ENCRYPTED and now they have have "${EXTENSION}" extension.
In order to recover your files you need to follow instructions below.
>> Sensitive Data
Sensitive data on your system was DOWNLOADED and it will be PUBLISHED if you refuse to cooperate.
Data includes:
- Employees personal data, CVs, DL, SSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients data, bills, budgets, annual reports, bank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...
Private preview is published here: http://alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion/[snip]
>> CAUTION
DO NOT MODIFY FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
YOUR DATA IS STRONGLY ENCRYPTED, YOU CAN NOT DECRYPT IT WITHOUT CIPHER KEY.
>> Recovery procedure
Follow these simple steps to get in touch and recover your data:
1) Download and install Tor Browser from: https://torproject.org/
2) Navigate to: http://sty5r4hhb5oihbq2mwevrofdiqbgesi66rvxr5sr573xgvtuvr4cs5yd.onion/?access-key=${ACCESS_KEY}
alphv2.txt
>> What happened?
Important files on your network was ENCRYPTED and now they have "${EXTENSION}" extension.
In order to recover your files you need to follow instructions below.
>> Sensitive Data
Sensitive data on your system was DOWNLOADED.
If you DON'T WANT your sensitive data to be PUBLISHED you have to act quickly.
Data includes:
- Employees personal data, CVs, DL, SSN.
- Complete network map including credentials for local and remote services.
- Private financial information including: clients data, bills, budgets, annual reports, bank statements.
- Manufacturing documents including: datagrams, schemas, drawings in solidworks format
- And more...
Private URL: http://alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion/[snip]
>> CAUTION
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
>> What should I do next?
Follow these simple steps to get everything back to normal:
1) Download and install Tor Browser from: https://torproject.org/
2) Navigate to: http://xnsbsjciylsg23zfmrv6ocuyh7ha5zexeouchlr3zsi5suda4arpeyqd.onion/?access-key=[snip]
alphv1.txt
Hello, [snip]
>> What happened?
Important files on your network was ENCRYPTED and now they have "${EXTENSION}" extension.
In order to recover your files you need to follow instructions below.
>> Sensitive Data
Sensitive data on your network was DOWNLOADED.
If you DON'T WANT your sensitive data to be PUBLISHED you have to act quickly.
Data includes:
- MICROS DATABASE, Accounting, Drawings
- Check Copies, Engineering, HR, Banking Information
- Payroll Scan, Sales and Marketing, Financia
- And more...
>> CAUTION
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
>> What should I do next?
1) Download and install Tor Browser from: https://torproject.org/
2) Navigate to: http://d75itpgjjfe2ys2qivqplbvmw3yyx7o5e4ppt2esit2lluhngulz4hqd.onion/?access-key=[snip]
JX34qQm7.txt
Data on Your network was exfiltrated and encrypted. Modifying encrypted files will result in permanent data loss! Get in touch with us ASAP to get an offer: 1. Download and install Tor Browser from https://www.torproject.org/ 2. Access User Panel at http://msv7eaydbdue7x6hos2kzbtwgoi7xmtuddlqgniqghs3qc54wajudwad.onion/?access-key=[snip] THIS IS YOUR PRIVATE USER PANEL ADDRESS, DO NOT SHARE IT WITH ANYONE! See also: Visit our Blog: http://alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion Social Media: https://twitter.com/search?q=%23alphv
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (731)
Search, filter and paginate the victim timeline for Alphv. Showing 701–731 of 731.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Albany Bank and Trust Company id2572 View details | United States | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Royal Laser id2559 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | mainland.com.hk id2541 View details | Hong Kong | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | CGT S.p.A. id2538 View details | Italy | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | themisautomation.com id2532 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OilTanking GmbH and Mabanaft GmbH id2531 View details | Germany | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | ipec.ro id2477 View details | Romania | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brookson Group id2459 View details | United Kingdom | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Moncler id2456 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Redbadge id2452 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Detroit Stoker id2415 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ballester Hermanos id2404 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Grand Bahama Port Authority id2403 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | D.F. Chase id2374 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FrenchGourmet id2373 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CED Group id2339 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NanoFocus id2338 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centaris.com id2331 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New City Commercial Corporation (NCCC) id2326 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | van Eupen Logistik id2325 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Buffers USA id2324 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hunter Douglas | hunterdouglas.com.au id2323 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Douglas Shaw & Associates id2322 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Solaris Management Consultants id2316 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unified Technologies id2315 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Uriach id2314 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SNOP GROUP id2313 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Inetum id2245 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Strataworldwide.com id2242 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RCMS id2241 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SVA Jean Rozé id698 View details | France | Other | — | |
|
No additional victim description available. |
|||||