🇷🇺BlackCat
🇷🇺 BlackCat is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 8 detection use cases to this actor across 12 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-04-20 to 2026-04-20.
crit 1
8Use cases
1Articles
12Techniques
0IOCs
Known aliases
BlackCatALPHVALPHV-BlackCatNoberus
Top techniques
All other tracked techniques
Detection use cases (8)
BlackCat/ALPHV Rust encryptor launch via --access-token credential gate BlackCat/ALPHV pre-encryption recovery inhibition + safeboot reboot cluster Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual childrenThreat-intel articles (1)
crit What the ransom note won’t say · 2026-04-20