LIVE: New phishing campaigns targeting mobile users β€”View latest threats β†’

Back to Threats
CriticalπŸ” RansomwareNEW

BlackCat/ALPHV Ransomware: RaaS & Triple Extortion

BlackCat (ALPHV) ransomware-as-a-service uses triple extortion and Rust-based encryption to hit hospitals and casinos, demanding millions in Bitcoin ransoms.

Published: 1 June 2026Last updated: 20 March 2026

What Is This Threat?

BlackCat (also known as ALPHV) emerged in late 2021 as one of the most technically sophisticated ransomware operations ever seen. It was the first major ransomware written in the Rust programming language, making it highly customizable, harder to detect, and capable of attacking Windows, Linux, and VMware ESXi servers simultaneously.

BlackCat operated as RaaS with affiliates keeping 80–90% of ransom payments β€” far more generous than competitors, which attracted the most skilled criminal hackers. It introduced triple extortion: encrypt files, steal and threaten to publish data, and launch DDoS attacks against victims or contact their customers directly.

Most Significant Attacks

MGM Resorts International β€” September 2023:

A BlackCat affiliate called Scattered Spider (a group of English-speaking young adults from the US and UK) gained access to MGM's systems through a single 10-minute phone call to the IT helpdesk, social engineering a password reset. They then deployed BlackCat ransomware.

  • MGM's casino floors in Las Vegas went dark: slot machines stopped working, hotel key cards failed, digital check-in systems went offline.
  • Disruption lasted 10+ days.
  • MGM refused to pay; total estimated losses: over $100 million.
  • MGM's CEO later testified the breach lasted months and affected millions of customers' personal data.
  • Caesars Entertainment β€” September 2023:

    Hit by the same Scattered Spider affiliate days before MGM. Caesars quietly paid approximately $15 million (half of the demanded $30 million) to avoid disruption. The attack was only disclosed because US SEC regulations required it.

    Change Healthcare β€” February 2024:

    The most damaging healthcare cyberattack in US history. Change Healthcare (a subsidiary of UnitedHealth Group) processes 1 in 3 US medical claims. A BlackCat affiliate compromised their systems via stolen credentials on a Citrix portal that lacked MFA.

  • US healthcare payment processing was disrupted for weeks β€” pharmacies couldn't process prescriptions, hospitals couldn't get paid.
  • 100 million Americans' health data was stolen β€” the largest healthcare data breach in US history.
  • UnitedHealth paid a $22 million ransom in Bitcoin.
  • Then BlackCat exit-scammed their own affiliate β€” the core developers took the $22M and disappeared without paying the affiliate's 80% share, effectively ending the operation.
  • UnitedHealth's total estimated losses from the attack: $870 million.
  • FBI Takedown β€” December 2023:

    The FBI disrupted BlackCat's infrastructure, seizing servers and creating decryption tools for over 500 victims worldwide. However, BlackCat briefly relaunched before the Change Healthcare attack, then collapsed after the exit scam in March 2024.

    What Made BlackCat Different

  • Rust-based code: Easily recompiled to evade antivirus signatures and attack multiple OS platforms.
  • Affiliate portal: A slick web dashboard for criminal affiliates to manage victims, track payments, and customize ransomware builds.
  • Scattered Spider affiliate: Demonstrated that social engineering (not just hacking) is the most effective entry point β€” a phone call defeated MGM's entire technical security stack.
  • Exit scam: Even criminal organizations betray each other; the $22M exit scam disrupted the RaaS ecosystem.
  • Red Flags for Organizations

  • Unusual helpdesk password reset requests, especially for IT admin or privileged accounts.
  • Suspicious Citrix, VPN, or remote desktop logins from unusual locations.
  • Large-scale file renaming or encrypted file extensions appearing across network shares.
  • Ransom notes appearing on servers demanding contact via Tor browser.
  • How to Protect Yourself

    • Enforce MFA on every remote access system without exception β€” the Change Healthcare breach happened because a Citrix portal had no MFA on a single account
    • Train helpdesk staff to verify caller identity through a callback procedure before resetting any privileged account credentials β€” the MGM attack started with a phone call
    • Implement privileged access management (PAM) so that even compromised helpdesk staff cannot reset IT admin accounts without additional verification
    • Monitor for credential stuffing and anomalous logins using SIEM or identity threat detection tools
    • Test incident response plans specifically for ransomware scenarios β€” MGM's slow recovery was partly due to having to rebuild systems they had not prepared for fast restoration

    What to Do If Affected

    1. 1.Isolate affected systems immediately and preserve memory dumps for forensic analysis before rebooting
    2. 2.Check the FBI's decryption tool released after the December 2023 takedown β€” it may work on some BlackCat variants
    3. 3.Report to CISA (cisa.gov) if in the US, or your national cybersecurity authority (Austria: cert.at, Germany: BSI, Ukraine: CERT-UA)
    4. 4.Do not pay ransom without exhausting free decryption options and receiving legal advice β€” BlackCat's own exit scam shows even paying does not guarantee outcome
    5. 5.Notify affected individuals and regulators if health or personal data was exfiltrated β€” US HIPAA and EU GDPR require breach notification within specific timeframes
    #BlackCat#ALPHV#ransomware#RaaS#MGM#Change Healthcare#Rust#triple extortion