{"id":7232,"date":"2022-09-06T07:22:38","date_gmt":"2022-09-06T14:22:38","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=7232"},"modified":"2023-04-20T01:49:54","modified_gmt":"2023-04-20T08:49:54","slug":"all-about-blackcat-alphav-ransomware","status":"publish","type":"post","link":"https:\/\/10.42.32.162\/articles\/all-about-blackcat-alphav-ransomware\/","title":{"rendered":"All About BlackCat (AlphaV) Ransomware"},"content":{"rendered":"

Did you know that the BlackCat ransomware group breached 60+ organizations in a single month?<\/strong><\/p>\n

Healthcare, public health, government, or energy\u2014the group has stopped at nothing, and has made ransom demands ranging from $400,000 to $3 million USD. Our research shows that the BlackCat group exploits vulnerabilities in Windows operating systems and servers, exchange servers, and Secure Mobile Access products.\u00a0<\/strong>Read on to learn how Securin can help you ward off such attacks.<\/strong><\/p>\n

BlackCat, also known as AlphaV, ALPHV, AlphaVM, ALPHV-ng, or Noberus, is a ransomware group that garnered the tag \u201cMost Sophisticated Ransomware of 2021\u201d within two months of its public footprint. Since being first spotted in November 2021, the BlackCat group has slowly made its way to the top of the charts. Researchers have also suggested that the group might have strong connections with REvil, DarkSide, BlackMatter, and Conti groups.<\/p>\n

Recent Updates<\/h2>\n

The BlackCat group has been constantly adding victims to its dark leak site. Read more about BlackCat ransomware attacks<\/a>.<\/p>\n

BlackCat: A Cheat Sheet<\/h2>\n
    \n
  1. \n

    BlackCat has the methods to exploit five vulnerabilities – CVE-2016-0099, CVE-2019-7481, CVE-2021-31207, CVE-2021-34473, and CVE-2021-34523.<\/p>\n<\/li>\n

  2. \n

    Interestingly, three vulnerabilities are of high severity. Although not of the critical severity category, they need to take precedence in the patching process owing to the associated threat context.<\/p>\n<\/li>\n

  3. \n

    CVE-2021-31207, CVE-2021-34473, and CVE-2021-34523 are ProxyShell vulnerabilities known for their dangerous exploitation in vulnerability chaining<\/a> attacks and have multiple threat actor associations.<\/p>\n<\/li>\n

  4. \n

    CVE-2016-0099 is a six-year-old privilege escalation vulnerability in older versions of Microsoft Windows, which are still widely used.<\/p>\n<\/li>\n

  5. \n

    CVE-2019-7481 is an SQL injection vulnerability in SonicWall Secure Remote Access devices that have reached their end of life. With no active support from the vendor, this vulnerability needs extra attention or a complete version overhaul.<\/p>\n<\/li>\n

  6. \n

    The ransomware is deployed by APT groups: FIN7, FIN12, DEV-0504, and DEV-0237, to intensify their attacks.<\/p>\n<\/li>\n<\/ol>\n

    \"\"<\/p>\n

    How Does BlackCat Attack?<\/h2>\n

    Below, we outline the group\u2019s attack techniques and tactics.<\/p>\n

    \n

    Reconnaissance: TA0043<\/strong><\/p>\n