ZeroFox Intelligence Flash Report - ALPHV Ransomware and Digital Extortion Operations Disrupted
|by Alpha Team

ZeroFox Intelligence Flash Report - ALPHV Ransomware and Digital Extortion Operations Disrupted
Product Serial: F-2023-12-19a
TLP:CLEAR
In this flash report, ZeroFox researchers provide updates around a joint international law enforcement effort to seize the victim leak site for the ALPHV ransomware group and what this likely means for the group's activities.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- The victim leak site associated with Ransomware and Digital Extortion (R&DE) collective ALPHV has been seized by the Federal Bureau of Investigation (FBI) in a takedown operation that involved law enforcement (LE) agencies from the United Kingdom, Denmark, Germany, Spain, and Australia.
- ALPHV has publicly downplayed the significance of the operation, claiming the seized infrastructure is not used and is outdated.
- This latest takedown operation follows numerous incidents of ALPHV victim site disruption in December 2023, which has very likely contributed to the significantly reduced attack tempo observed by ZeroFox and the pivoting of affiliates toward other Ransomware-as-a-Service (RaaS) offerings.
Tags: tlp:clear, DDW Ransomware, threat actor