# ALPHV

> As of 2026-08-28, ALPHV is a threat actor tracked by Threadlinqs Intelligence across 7 threats spanning ransomware, threat actor, cybercrime. Also known as BlackCat, Ryan Goldberg. ATT&CK coverage spans 91 techniques across 15 tactics in 7 of 7 tracked threats. Most-observed techniques: T1490 (Inhibit System Recovery), T1486 (Data Encrypted for Impact), T1657 (Financial Theft).

- **Tracked threats:** 7
- **Categories:** RANSOMWARE, THREAT_ACTOR, CYBERCRIME
- **Also known as:** BlackCat, Ryan Goldberg
- **As of:** 2026-08-28

## ATT&CK techniques observed

91 techniques observed across 7 of 7 tracked threats. Tactics: Discovery (18), Credential Access (8), Impact (8), Collection (7), Defense Impairment (7), Stealth (formerly Defense Evasion) (7).

- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 7 of 7 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 6 of 7 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 6 of 7 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 5 of 7 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 4 of 7 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 4 of 7 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 4 of 7 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 4 of 7 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 4 of 7 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 3 of 7 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 3 of 7 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 7 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 3 of 7 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 3 of 7 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 3 of 7 tracked threats

## Tracked threats

- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — HIGH
- [Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months](https://intel.threadlinqs.com/threat/TL-2026-1294) — HIGH
- [Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims](https://intel.threadlinqs.com/threat/TL-2026-1264) — MEDIUM
- [Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin](https://intel.threadlinqs.com/threat/TL-2026-1174) — MEDIUM
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme](https://intel.threadlinqs.com/threat/TL-2026-1166) — MEDIUM
- [Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK Abuse](https://intel.threadlinqs.com/threat/TL-2026-2191) — HIGH
- [Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)](https://intel.threadlinqs.com/threat/TL-2026-0810) — HIGH

## Related CVEs

7 CVEs referenced by tracked ALPHV activity.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/ALPHV
