ZeroFox Intelligence Brief - Ransomware & Digital Extortion - ALPHV Targeting
|by Alpha Team

ZeroFox Intelligence Brief - Ransomware & Digital Extortion - ALPHV Targeting
Product Serial: B-2023-12-05a
TLP:CLEAR
In this Intelligence Brief, ZeroFox researchers provide updates on ALPHV targeting, including a profile of the group, regional targeting statistics, associated IOCs and TTPs, and recommendations for protecting against the group’s activities.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- ALPHV has been one of the most prominent ransomware and digital extortion (R&DE) threats to the majority of industries globally.
- ALPHV attacks as a proportion of total R&DE activity is on a slight downward trajectory. Likely contributing to this is the host of newer, highly-active threat collectives that have emerged in 2023, which are likely drawing affiliates from prominent, established ransomware-as-a-service (RaaS) offerings.
- The threat from ALPHV will almost certainly remain significant over the next two quarters, as affiliates continue a high attack tempo. Security teams should also monitor for an increasingly diverse spectrum of R&DE operations.
Tags: tlp:clear, threat actor, DDW Ransomware