The company ZeroFox conducted a study and found that ALPHV/BlackCat was the second most popular ransomware strain (in terms of attacks) in North America and Europe between January 2022 and October 2023. At least that was the case until the group's sites were taken down .

The analysis found that ALPHV was associated with approximately 11% of all ransomware and digital extortion (R&DE) in North America and 6% in Europe. The top spot was occupied by LockBit ransomware.
Additionally, according to the report, a significant increase in global activities of the BlackCat ransomware gang throughout 2023, although a relative decline was noted in Q3 2023.
See also: LockBit: Recruits affiliates from BlackCat/ALPHV and NoEscape ransomware
The biggest focus of the group during the above period was on organizations in North America.
How will the ALPHV ransomware be affected by the infrastructure disruption?
Earlier this month, it was reported that the ransomware-as-a-service (RaaS) gang suffered an online outage, which intelligence experts attributed to law enforcement actions. The hackers denied these claims.
Daniel Curtis , Senior Intelligence Analyst at ZeroFox, emphasized that website outages are a fairly common occurrence and will likely only result in a temporary suppression of the threat .
“The extortion group’s blog is currently experiencing long periods of downtime, which happens from time to time in these ecosystems and is usually the result of an unknown law enforcement operation, inter-cartel dispute, or network maintenance,” he noted.
Curtis added that even if the group can't return to the way it was before, it will quickly turn to other ransomware to continue targeting victims.
See also: HTC Global Services: Is ALPHV/BlackCat ransomware behind the attack?

What techniques does the BlackCat group usually use?
Exploiting vulnerabilities exposed on the Internet: Hackers exploit a number of vulnerabilities, which allow remote code execution and elevation of privileges and access controls .
Social engineering: Hackers use various social engineering, such as spear phishing, mass vishing, etc. to deliver and execute malware remotely.
Malware-as-a-Service (MaaS): ALPHV team partners leverage MaaS Emotetto launch first-stage breaches.
External Remote Services: Attackers exploited Remote Desktop Protocol (RDP) to gain access to victims' networks by leveraging legitimate user credentials.
Drive-by Compromise: Some affiliates also use this method.
Valid Accounts: Attackers have used compromised credentials to bypass access controls, create persistence, escalate privileges, and evade detection.

Ransomware protection
One of the most important measures that can be taken to protect against ransomware attacks is education user. Users should be aware of the latest threats and learn how to recognize suspicious emails or malicious files that may contain ransomware.
Another important measure is to install up-to-date antivirus software and security programs. Antivirus and scheduled updates can detect and prevent ransomware from entering the system.
See also: Tipalti: Investigates allegations of BlackCat ransomware gang breach
Also, regularly backing up important data is crucial. If a computer falls victim to ransomware, backups can be used to restore data without paying a ransom.
Additionally, network protection is important. This can be achieved through the use of advanced protection technologies, such as firewalls, intrusion detectors, and anti-spam filters.
Finally, browsing the internet carefully and avoiding obviously dangerous websites and downloading software from untrusted sources can also reduce the risk of ransomware executing on the system.
Source: www.infosecurity-magazine.com
