Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

ALPHV

Also known as:BlackCatRyan Goldberg

As of 2026-08-28, ALPHV is a threat actor tracked by Threadlinqs Intelligence across 7 threats spanning ransomware, threat actor, cybercrime. Also known as BlackCat, Ryan Goldberg. ATT&CK coverage spans 91 techniques across 15 tactics in 7 of 7 tracked threats. Most-observed techniques: T1490 (Inhibit System Recovery), T1486 (Data Encrypted for Impact), T1657 (Financial Theft).

Tracked threats
74 high · 3 medium
First seen
2026-06-15
Last seen
2026-07-26
ATT&CK techniques
91across 7 of 7 threats
Related CVEs
7Referenced by its activity
7 tracked threat(s) · Categories: RANSOMWARE, THREAT_ACTOR, CYBERCRIME

Activity timeline

ALPHV appears in 7 tracked threats between and ; the busiest month was 2026-07 with 5 reports.

ATT&CK techniques observed

91 techniques observed across 7 of 7 tracked threats · Discovery (18), Credential Access (8), Impact (8), Collection (7), Defense Impairment (7), Stealth (formerly Defense Evasion) (7)
  • T1490 Inhibit System Recovery — Impactobserved in 7 of 7 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 6 of 7 tracked threats
  • T1657 Financial Theft — Impactobserved in 6 of 7 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 5 of 7 tracked threats
  • T1047 Windows Management Instrumentation — Executionobserved in 4 of 7 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 4 of 7 tracked threats
  • T1485 Data Destruction — Impactobserved in 4 of 7 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 7 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 7 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 7 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 3 of 7 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 3 of 7 tracked threats

Tracked threats

Related CVEs

7 CVEs referenced by tracked ALPHV activity