The ALPHV BlackCat ransomware is the newest group that has drawn attention for having the most advanced malware in years. The group was only the third group to be able to write their strain in Rust language, this language is more secure and reliable than the ones used by the other ransomware groups, which use C and C++ language.

The group is still quite new, but already shows great potential to reach the same level as the REvil ransomware Sodinokibi and Darkside have reached. BlackCat uses the tactic of RaaS (Ransomware as a Service), the group has been offering its malware on Dark Web forums.

The ALPHV ransomware is designed to attack Windows, Linux and VMWare ESXi operating systems. Few groups have achieved this feat.

In addition to all these features, the ransomware moves laterally through a company’s internal network, disabling all company protections, and then installs copies of itself on multiple computers to reach as many files as possible.

The group disclosed in a forum that its encryption can be done in four different ways, which are:

  • Full – complete encryption of the file. The most secure and slowest.
  • Fast – encryption of the first N megabytes. Not recommended for use, the most insecure solution possible, but the fastest.
  • DotPattern – encryption of N megabytes by M-step. If set incorrectly, Fast can work worse in both speed and cryptographic strength.
  • Auto – Depending on the type and size of the file, the cabinet (on both Windows and * nix / ESXi) chooses the best strategy (in terms of speed / security) to process the files.

This shows how serious and advanced this group is compared to other groups. Besides the RaaS Tactic, the group also uses double extortion, which consists of encrypting and extracting files that will be used for blackmail, if the victim does not pay the ransom imposed by the group, the files will be leaked on a website created specifically for the victim company.

Recover Files Encrypted by ALPHV BlackCat Ransomware

The ALPHV BlackCat ransomware has shown itself to be one of the most worrisome groups in the near future, even though they do not have major attacks today, but from everything they have shown their destructive ability is very large.

