The group behind the BlackCat ransomware , also known as ALPHV , has confirmed that it was once part of the infamous BlackMatter/DarkSide ransomware operation .

See also: FBI, CISA and NSA issue advisories on BlackMatter ransomware attacks
The BlackCat/ALPHV group is a new ransomware group with novel features, launched in November 2021 and developed in the Rust, which is unusual for ransomware infections.
The ransomware executable is highly adaptable, with different encryption methods and options, allowing it to attack a wide range of corporate environments.
While the gang calls itself ALPHV, security researcher MalwareHunterTeamnamed the ransomware BlackCat after the image of a black cat used on each victim's Tor payment page.
Since then, this ransomware has been known as BlackCat when discussed in the media or by security researchers.
Already since the release of the BlackCat ransomware in November, a representative of the LockBit stated that ALPHV/BlackCat is a new brand of DarkSide/BlackMatter.
See also: Researchers provided decryption tool to victims of BlackMatter ransomware

And recently The Record published an interview with the ALPHV/BlackCat gang, which confirmed suspicions that they were affiliated with the DarkSide/BlackMatter gang.
While the operators of BlackCat claim that they were simply affiliates of DarkSide/BlackMatter, who started their own ransomware operation, some security researchers do not believe this.
Emsisoft threat analyst Brett Callowbelieves that BlackMatter replaced its development team after Emsisoft exploited a vulnerability that allowed victims to recover their files for free, resulting in the gang losing millions of dollars in ransom.
In the past, it was possible to prove that different ransomware operations were related by looking for code similarities in the encryptor's code.
As the BlackCat cryptographer has been built from the ground up in the Rust programming language, Fabian Wosar said these coding similarities no longer exist.
See also: Marketron: BlackMatter ransomware targeted software provider
However, Wosar said there are similarities in the features and configuration files, claiming that it is the same group behind the BlackCat and DarkSide/BlackMatter ransomware operations.
Regardless of whether they are just old affiliates that decided to start their own ransomware operation or a rebrand of DarkSide/BlackMatter, they have proven themselves capable of carrying out large corporate attacks and are quickly accumulating victims.
