Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ BlackCat

🇷🇺BlackCat

🇷🇺 BlackCat is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 8 detection use cases to this actor across 12 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-04-20 to 2026-04-20.

crit 1
View full actor card → All threat actors
8Use cases
1Articles
12Techniques
0IOCs

Known aliases

BlackCatALPHVALPHV-BlackCatNoberus

Top techniques

All other tracked techniques

Detection use cases (8)

BlackCat/ALPHV Rust encryptor launch via --access-token credential gate AI · profile SΣDD BlackCat/ALPHV pre-encryption recovery inhibition + safeboot reboot cluster AI · profile SDD Phishing-link click correlated to endpoint execution Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal

Threat-intel articles (1)