MITRE ATT&CK G1014
Aliases: BlackCat, Noberus
Official Attribution Source: DOJ Takedown & CISA Joint Advisory AA23-353A

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
1
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G1014 (ALPHV / BlackCat).
  • Linked to 1 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to ALPHV / BlackCat Technique frequencies extracted from verified indictments for ALPHV / BlackCat. T1078 Valid Accounts 1 incidents T1486 Data Encrypted for Impact 1 incidents T1567 Exfiltration Over Web Service 1 incidents T1041 Exfiltration Over C2 Channel 1 incidents T1133 External Remote Services 1 incidents T1087 Account Discovery 1 incidents
Technique frequencies extracted from verified indictments for ALPHV / BlackCat.
ATT&CK Techniques Mapped to ALPHV / BlackCat
Technique Frequency
T1078 Valid Accounts 1 incidents
T1486 Data Encrypted for Impact 1 incidents
T1567 Exfiltration Over Web Service 1 incidents
T1041 Exfiltration Over C2 Channel 1 incidents
T1133 External Remote Services 1 incidents
T1087 Account Discovery 1 incidents

Prosecution Cases Attributed to This Actor

alleged 2024-02-21

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

6 techniques View case →

Treasury OFAC Sanctions Actions

ALPHV / BlackCat Leadership 2024-03-27

Up to $10,000,000 reward for information leading to identification of leaders of the ALPHV/BlackCat ransomware group responsible for Change Healthcare outage.

Official Treasury Press Release ↗