logo

ALPHV ransomware gang fakes own death, fools no one

ID: 96706ac1-512b-5e25-ac7a-bb59a196f69b

STIX ID: report--96706ac1-512b-5e25-ac7a-bb59a196f69b

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2024-03-06

Date Updated: 2026-04-28

...
...

The article describes a high-impact incident involving the ALPHV/BlackCat ransomware group: an affiliate reportedly attacked Change Healthcare (causing significant disruption), a claimed $22M (350 BTC) payment, subsequent affiliate account lockouts, and the appearance of a likely fake "THIS WEBSITE HAS BEEN SEIZED" banner on ALPHV's dark web site—researchers suspect the gang is staging a takedown to cover an exit scam while selling its ransomware source code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.