Close Menu
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Trump White House ballroom project boosted by YouTube

October 22, 2025

NHL strikes prediction market deals with Kalshi, Polymarket

October 22, 2025

New research shows, AI assistants make widespread errors about news

October 22, 2025
Facebook X (Twitter) Instagram
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports
Nabka News
Home » Profiled actors: menuPass and ALPHV/BlackCat
Trend

Profiled actors: menuPass and ALPHV/BlackCat

i2wtcBy i2wtcJune 27, 2024No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
Follow Us
Google News Flipboard Threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


The structural complexity of the menuPass/APT10 Umbrella illustrates one of the fundamental challenges of threat intelligence: threat actors are not always well-defined or homogenous.

ALPHV/BlackCat brings a unique layer of complexity to the puzzle, as it is sometimes viewed as Rust-based ransomware available as a service, and sometimes referred to as a threat actor group responsible for creating and monitoring what is offered as a service.

MITRE Engenuity places ALPHV/BlackCat squarely in the latter category, explaining that “ALPHV/BlackCat, a ransomware-as-a-service, emerged in 2021 to target a variety of industries with a flexible ransomware strain capable of cross-platform attacks against Windows, Linux, and VMware systems.”

MITRE Engenuity borrowed “signature behaviors” from both menuPass and ALPHV/BlackCat to engineer “compromises of multiple subsidiaries through overlapping operations focused on evading defenses, exploiting trust relationships, encrypting data, and preventing system recovery.”

The evaluation of menuPass employed a combination of Living-Off-The-Land techniques, custom, fileless malware, anti-analysis and abuse of trusted third-party relationships to access credentials, as well as mimicking ALPHV/BlackCat defense evasion techniques, in addition to exfiltrating data, encrypting data, destroying data and impeding system recovery.

Where are they now?

While the TTPs used in MITRE Engenuity Managed Services assessments are well known and documented, threat actors are not fixed in time. Trend™ Research continues to track both menuPass and ALPHV/BlackCat.

The nation-state-sponsored cyberespionage group menuPass (APT10 Umbrella) constantly changes targets depending on the nation state that is funding it. Its objectives are essentially the same: information brokering, identity theft, and related activities. In 2018, members of the group were reportedly indicted, but the group itself has since resurfaced, making headlines for an apparent (failed) intrusion into an Indian vaccine manufacturer during the pandemic, and then for its role in A41APT’s multi-industry data theft campaigns.

Because menuPass has so many subgroups and offshoots, it would be inaccurate to attribute specific campaigns to this umbrella organization or to definitively identify a single motivation, toolset, or TTPs.

The ALPHV/BlackCat group that “inspired” the MITRE Engenuity attack approach in this year’s managed services evaluation has disbanded, splintering amid internal fighting over the ransom paid by Change Healthcare in winter 2024. Still, ransomware is a lucrative business, so ransomware threat actor groups tend to burn out, regroup, and re-emerge.

In general, threat actors’ TTPs are becoming increasingly similar in response to cybercrime “best practices” and evolving security technologies.

Threat information is important

Protecting against attackers like menuPass and ALPHV/BlackCat requires a combination of advanced cybersecurity tools and cutting-edge threat intelligence. The importance of the second part of this formula cannot be underestimated. Understanding the source of the threat, its motivation, and the attacker’s next move will help you make better and more effective decisions to track and mitigate the threat.

Trend Micro™ Managed Detection and Response (MDR) services are built on the Trend Vision One™ platform and are based on threat intelligence from Trend Research and findings from the Trend Micro™ Zero-Day Initiative™ (ZDI). Trend Vision One provides automated detection and response capabilities, while Trend Research provides insight into how threats behave and how to respond.

Beyond advanced persistent threats and ransomware, our current focus for Trends Research is securing AI, cloud and network threats, and understanding the full scope of the risk landscape – what it consists of and how it is changing. We are committed to continually providing cybersecurity insights, delivering the most effective managed security services possible, and driving advancements in security technology.

Next steps

To learn more about Trend MDR, XDR, and other related topics, check out these additional resources:



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
i2wtc
  • Website

Related Posts

Trend

Meta lays off 600 employees within AI unit

October 22, 2025
Trend

Airbnb’s Chesky says ChatGPT isn’t ‘quite robust enough’ to integrate

October 22, 2025
Trend

Hundreds of public figures including ‘AI godfathers’ urge ‘superintelligence’ ban

October 22, 2025
Trend

Fund managers are betting on stocks despite AI bubble risks

October 22, 2025
Trend

Netflix ‘all in’ on leveraging AI in its streaming platform

October 22, 2025
Trend

Microsoft CEO Satya Nadella’s total comp rises to $96.5 million

October 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

House Republicans unveil aid bill for Israel, Ukraine ahead of weekend House vote

April 17, 2024

Prime Minister Johnson presses forward with Ukraine aid bill despite pressure from hardliners

April 17, 2024

Justin Verlander makes season debut against Nationals

April 17, 2024

Tesla lays off 285 employees in Buffalo, New York as part of major restructuring

April 17, 2024
Don't Miss

Trump says China’s Xi ‘hard to make a deal with’ amid trade dispute | Donald Trump News

By i2wtcJune 4, 20250

Growing strains in US-China relations over implementation of agreement to roll back tariffs and trade…

Donald Trump’s 50% steel and aluminium tariffs take effect | Business and Economy News

June 4, 2025

The Take: Why is Trump cracking down on Chinese students? | Education News

June 4, 2025

Chinese couple charged with smuggling toxic fungus into US | Science and Technology News

June 4, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to NabkaNews, your go-to source for the latest updates and insights on technology, business, and news from around the world, with a focus on the USA, Pakistan, and India.

At NabkaNews, we understand the importance of staying informed in today’s fast-paced world. Our mission is to provide you with accurate, relevant, and engaging content that keeps you up-to-date with the latest developments in technology, business trends, and news events.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Trump White House ballroom project boosted by YouTube

October 22, 2025

NHL strikes prediction market deals with Kalshi, Polymarket

October 22, 2025

New research shows, AI assistants make widespread errors about news

October 22, 2025
Most Popular

Exhibition marking 80th anniversary of victory against Japanese aggression, fascism launched in Beijing-Xinhua

July 9, 2025

China completes “power expressway loop” around southern Xinjiang desert-Xinhua

July 13, 2025

Green Agriculture Chain area at China’s supply chain expo-Xinhua

July 18, 2025
© 2025 nabkanews. Designed by nabkanews.
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us

Type above and press Enter to search. Press Esc to cancel.