logo

TTPs Associated With a New Version of the BlackCat Ransomware

ID: a987fa37-84b1-5df2-b798-0e3b81ccad26

STIX ID: report--a987fa37-84b1-5df2-b798-0e3b81ccad26

Feed Name: SecurityScorecard Blog

Threat Score
75/100

Date Published: 2025-02-24

Date Updated: 2026-04-29

...
...

This DFIR report details a BlackCat/ALPHV ransomware engagement: attackers exploited vulnerable Microsoft Exchange servers to drop webshells, used credential theft (Mimikatz or LSASS dumps) and network discovery to move laterally via RDP, staged data by compressing with WinRAR/7zip, exfiltrated with rclone and MEGAsync, installed legitimate tools (MobaXterm, Process Hacker) to evade detection, and ran a new BlackCat build that supports a “--safeboot” parameter and restart/sleep behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.