Breaking

ALPHV BlackCat Ransomware – The most sophisticated ransomware of 2021

A new ransomware operation is underway, it is named as the ALPHV aka BlackCat ransomware and is found to be the most sophisticated ransomware of 2021. It comes with high customization allowing attackers to manipulate victims with a new model of ransomware every time.

The ransomware exe is written in Rust that allows attackers to have better control as Rust provides better performance and memory safety for the malware.

MalwareHunterTeam was first to discover the new ransomware and published a tweet about the same. In the tweet, the researchers have claimed that there are already many victims for BlackCat and the malware UI looks like they are from 80s.

The ALPHV BlackCat ransomware was officially named as ALPHV and is now being actively marketed via Russian hacking forums. Just like other Ransomware-as-a-Service the BlackCat operators also recruit affiliates for corporate attacks and encryption.

Features of ALPHV BlackCat ransomware

The BlackCat ransomware comes with some major features that makes it unique in the dark web market. This ransomware is a command line driven, manually operated, and highly customizable. It uses different encryption procedures, can laterally spread between devices, affect VMs and can erase ESXi snapshots thus preventing any recovery attempts.

The different type of encryption include, Full File Encryption, Fast Encryption for the first N Megabytes, DotPattern Encryption, Auto-encryption, Smart Pattern Encryption, ChaCha20 and AES.

The attackers can even configure the ALPHV ransomware with domain credentials which can be used to encrypt other devices in the network, which later deploys ransomware by extracting the files. APLHV BlackCat uses the Windows Restart Manager API to close handle the process or shutdown Windows services. The ransom note for BlackCat comes as ‘RECOVER-[extension]-FILES.TXT’.

You can see the ransom note below,

More on BlackCat ransomware

BlackCat is found to be very sophisticated ransomware and could fill the empty space of BlackMatter and REvil ransomware operators after their recent shutdown. ALPHV uses a triple-extortion tactic as they steal the data before encrypting one and then threaten to publish the same if the ransom isn’t paid.

And the ransom demands ranges between $400,000 to $3 million payable via Bitcoin or Monero. So it is important for enterprises and business to keep their security up and active to avoid BlackCat into their network.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit. You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends
William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

Recent Posts

Best Microsoft Intune Alternatives: Top 5 MDMs to Consider

Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…

1 day ago

Top 7 Best Smartphones with Best Security Features in 2024

Discover the top 7 smartphones of 2024 with best security features, offering privacy, performance, and…

3 weeks ago

Top 11 Log Management Tools for Efficient System Management

Discover the top 11 log management tools for efficient system management and monitoring. Learn about…

2 months ago

Top 5 Threat Intelligence Tools For 2024

Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…

2 months ago

Privileged Access Management: 5 Best PAM Solutions in the Market

Explore the top 5 best PAM Tools, market trends, and expert insights to secure the…

2 months ago

Apple Device Management: Top Solutions for iOS and macOS Management

Explore the top solutions for Apple Device Management including to iOS Device Management and macOS…

2 months ago