Back to Resources

SentinelOne Vs. BlackCat Ransomware – Mitigation and Rollback

⚔️ See how SentinelOne mitigates and rolls back BlackCat Ransomware. BlackCat (aka AlphaVM, AlphaV) is a newly established RaaS (Ransomware as a Service) with payloads written in Rust. Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (aka Cobalt Strike) or via exposed (and vulnerable) applications.

BlackCat currently supports both Windows and Linux operating systems. Samples analyzed require an “access token” to be supplied as a parameter upon execution. This is similar to threats like Egregor, and is often used as an anti-analysis tactic. In addition, BlackCat (on Windows) will attempt to Delete VSS (Volume Shadow Copies), as well as enumerate local/accessible drives to affect eligible files. Extensions on encrypted files can vary across samples. Infected users are instructed to connect to the attackers’ payment/support portal (via TOR).

Watch Now

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.