Activity timeline
ALPHV appears in 7 tracked threats between and ; the busiest month was 2026-07 with 5 reports.
ATT&CK techniques observed
- T1490 Inhibit System Recovery — Impactobserved in 7 of 7 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 6 of 7 tracked threats
- T1657 Financial Theft — Impactobserved in 6 of 7 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 5 of 7 tracked threats
- T1047 Windows Management Instrumentation — Executionobserved in 4 of 7 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 4 of 7 tracked threats
- T1485 Data Destruction — Impactobserved in 4 of 7 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 7 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 7 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 7 tracked threats
- T1135 Network Share Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 3 of 7 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 3 of 7 tracked threats
Tracked threats
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud StorageHIGH
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 MonthsHIGH
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five VictimsMEDIUM
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin MartinMEDIUM
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion SchemeMEDIUM
- Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK AbuseHIGH
- Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)HIGH