MITRE ATT&CK G1014
ALPHV / BlackCat
View MITRE Group Page ↗
Aliases: BlackCat, Noberus
Official Attribution Source: DOJ Takedown & CISA Joint Advisory AA23-353A
Key Facts
Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
1
OFAC designations
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G1014 (ALPHV / BlackCat).
- Linked to 1 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1078 Valid Accounts | 1 incidents |
| T1486 Data Encrypted for Impact | 1 incidents |
| T1567 Exfiltration Over Web Service | 1 incidents |
| T1041 Exfiltration Over C2 Channel | 1 incidents |
| T1133 External Remote Services | 1 incidents |
| T1087 Account Discovery | 1 incidents |
Prosecution Cases Attributed to This Actor
alleged 2024-02-21
ALPHV / BlackCat Ransomware Attack on Change Healthcare
Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.
6 techniques
View case →
Treasury OFAC Sanctions Actions
ALPHV / BlackCat Leadership 2024-03-27
Up to $10,000,000 reward for information leading to identification of leaders of the ALPHV/BlackCat ransomware group responsible for Change Healthcare outage.
Official Treasury Press Release ↗