Duty Analyst: Joseph McCarthy

Blog

Insights & Blog

Research, detection engineering notes, and incident response lessons learned.

Latest

123 articles published.

BlackCat (ALPHV)

BlackCat, also known by its alias ALPHV, is one of the most sophisticated and dangerous ransomware groups currently active. First observed in late 2021, BlackCat has rapidly built a reputation for technical innovation, aggressive extortion tactics, and high-value targeting. It was the first major ransomware group to write its payload in Rust, allowing it to execute across both Windows and Linux/ESXi environments with high performance and stealth.

Cl0p

Cl0p is a high-impact ransomware group operating under a double extortion model, best known for its targeted exploitation of enterprise file transfer systems and public data leaks involving some of the world’s largest organisations. Active since at least 2019, Cl0p (also styled as Clop) operates a sophisticated, financially motivated operation that combines custom ransomware tooling, advanced vulnerability exploitation, and a well-maintained leak portal.

Ghostwriter / UNC1151

Ghostwriter, also tracked as UNC1151, is a cyber influence and espionage operation attributed to actors aligned with Belarus, with potential support or collaboration from Russian military intelligence. First publicly identified in 2017, Ghostwriter has conducted coordinated disinformation campaigns and cyber intrusions targeting political, military, and civil institutions across NATO member states, with particular focus on Poland, Lithuania, Latvia, and Ukraine.