#StopRansomware: ALPHV Blackcat
ID: 002c0a91-9e7f-5803-8220-a88ded104b6a
STIX ID: report--002c0a91-9e7f-5803-8220-a88ded104b6a
Feed Name: CISA Cybersecurity Advisories
The FBI, CISA, and HHS joint advisory documents active ALPHV/BlackCat ransomware-as-a-service activity, detailing affiliate TTPs (social engineering, credential theft, remote access tooling, Cobalt Strike, Evilginx2), cross-platform encryption capabilities (Windows, Linux, VMware), extensive IOCs (MD5/SHA1/SHA256 hashes, domains, and IP addresses), recent targeting trends (notably healthcare), and recommended mitigations and incident response actions to detect, contain, and recover from compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
