alphv

Ransomware
Fuenteransomware.live

Sobre el grupo

The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote their affiliate program, offering other actors the opportunity to engage in a 'new type of ransomware family' developed from scratch using the Rust programming language.<BR> <BR> Some clear evidence indicates that the actors behind this new ransomware are not new to cybercrime, and there were links to other affiliate programs such as DarkSide, BlackMatter, and REvil. (After several attacks against large companies, these groups faced pressure and arrests, necessitating the termination of their operations).<BR> <BR> As a security measure, the operators of ALPHV implemented the requirement for the execution of the ransomware payload by providing an 'access token,' which is supplied by the owners of the Ransomware-as-a-Service to the affiliate. This token is added to the victim's ransom note so that they can contact the threat actor responsible for encrypting the data.<BR> <BR> ALPHV affiliates employ double and triple extortion techniques, meaning the publication of the company's name on leak sites, threats of data leakage, and lastly, threats of DDoS attack

Vulnerabilidades explotadas

Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.

Impacto y víctimas

El grupo alphv tiene 11 víctimas de ransomware conocidas. Ve los sectores y países más afectados y las víctimas recientes.

11víctimas conocidas
11en Brasil
7sectores afectados
Sectores más atacados
Professional Services2
Technology2
Government & Defense2
Education2
Manufacturing1
Agriculture and Food Production1
Transportation1
Países más afectados
🇧🇷 Brasil11
Víctimas recientes
Prefeitura Municipal de ItabiraGovernment & Defense · BR · 2023-12-24
LCA ConsultoresProfessional Services · BR · 2023-11-24
ComflorestaAgriculture and Food Production · BR · 2023-11-06
BrData TecnologiaTechnology · BR · 2023-10-09
Grupo Cativa was hacked Huge amounts of critical information have been stolenManufacturing · BR · 2023-05-05
Fundação Carlos ChagasEducation · BR · 2023-04-26
Lisa Logística was hacked A great amount of critical information has been stolenTransportation · BR · 2023-04-21
IFPAEducation · BR · 2023-01-21
ELOTECH - HACKED AND MORE THEN 100 GB DATA LEAKED!Government & Defense · BR · 2022-12-24
RecordTVTechnology · BR · 2022-10-13
herccombrProfessional Services · BR · 2022-07-28

El grupo alphv usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →