Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

BlackCat

Also known as:ALPHVALPHV Ransomware Affiliates

As of 2026-07-26, BlackCat is a threat actor tracked by Threadlinqs Intelligence across 6 threats spanning ransomware, threat actor, threat intel. Also known as ALPHV, ALPHV Ransomware Affiliates. ATT&CK coverage spans 91 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), T1657 (Financial Theft).

Tracked threats
64 high · 2 medium
First seen
2026-06-15
Last seen
2026-07-26
ATT&CK techniques
91across 6 of 6 threats
Related CVEs
7Referenced by its activity
6 tracked threat(s) · Categories: RANSOMWARE, THREAT_ACTOR, THREAT_INTEL

Activity timeline

BlackCat appears in 6 tracked threats between and ; the busiest month was 2026-07 with 5 reports.

ATT&CK techniques observed

91 techniques observed across 6 of 6 tracked threats · Discovery (18), Credential Access (8), Impact (8), Stealth (formerly Defense Evasion) (8), Collection (7), Defense Impairment (6)
  • T1486 Data Encrypted for Impact — Impactobserved in 6 of 6 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 6 of 6 tracked threats
  • T1657 Financial Theft — Impactobserved in 5 of 6 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 6 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 6 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 3 of 6 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 3 of 6 tracked threats
  • T1047 Windows Management Instrumentation — Executionobserved in 3 of 6 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 6 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 3 of 6 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 3 of 6 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 3 of 6 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 3 of 6 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 3 of 6 tracked threats

Tracked threats

Related CVEs

7 CVEs referenced by tracked BlackCat activity