Alpha ransomware linked to NetWalker operation dismantled in 2021
ID: cda10c5b-7978-5fcf-bf9d-7b3f5d6ba49b
STIX ID: report--cda10c5b-7978-5fcf-bf9d-7b3f5d6ba49b
Feed Name: Bleeping Computer
Alpha ransomware, active since February 2023, has recently escalated by launching an extortion/data‑leak site listing nine victims and publishing stolen files; Symantec and other researchers identify significant code and TTP overlaps with the defunct Netwalker operation (PowerShell loader, payload execution flow, custom import tables, process/service termination, and similar payment portal phrasing). The report notes Alpha's evolving sophistication (random file extensions, messaging-based contact instructions), use of living‑off‑the‑land utilities for lateral movement and evasion, and concludes the group represents an emerging ransomware threat possibly tied to Netwalker code or developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
