November 17, 2023
1. BlackCat/ALPHV ransomware The BlackCat group is a sophisticated RaaS operation, active since November 2021, known for using a variety of methods to infiltrate victim networks, including exploiting known vulnerabilities, phishing attacks, and social engineering. Once inside a network, BlackCat operators typically use a combination of tools and techniques to move laterally, escalate privileges, and exfiltrate data. The group then deploys its ransomware payload, which encrypts the victim’s files.
BlackCat is implemented in the Rust programming language, which is efficient for file encryption and cross-platform compatibility.