MITRE ATT&CK G1014
Aliases: BlackCat, Noberus
Official Attribution Source: DOJ Takedown & CISA Joint Advisory AA23-353A

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
2
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
1
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G1014 (ALPHV / BlackCat).
  • Linked to 2 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to ALPHV / BlackCat Technique frequencies extracted from verified indictments for ALPHV / BlackCat. T1078 Valid Accounts 1 incidents T1486 Data Encrypted for Impact 1 incidents T1567 Exfiltration Over Web Service 1 incidents T1041 Exfiltration Over C2 Channel 1 incidents T1133 External Remote Services 1 incidents T1087 Account Discovery 1 incidents
Technique frequencies extracted from verified indictments for ALPHV / BlackCat.
ATT&CK Techniques Mapped to ALPHV / BlackCat
Technique Frequency
T1078 Valid Accounts 1 incidents
T1486 Data Encrypted for Impact 1 incidents
T1567 Exfiltration Over Web Service 1 incidents
T1041 Exfiltration Over C2 Channel 1 incidents
T1133 External Remote Services 1 incidents
T1087 Account Discovery 1 incidents

Prosecution Cases Attributed to This Actor

alleged 2024-02-21

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

6 techniques View case →
convicted 2024-02-21

Change Healthcare Ransomware Outage (ALPHV / BlackCat)

Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.

3 techniques View case →

Treasury OFAC Sanctions Actions

ALPHV / BlackCat Leadership 2024-03-27

Up to $10,000,000 reward for information leading to identification of leaders of the ALPHV/BlackCat ransomware group responsible for Change Healthcare outage.

Official Treasury Press Release ↗
OPERATIONAL DEFENSE

Targeted Defensive Hardening for ALPHV / BlackCat

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.