Threat Actor Database
#86

ALP-001

Ransomware

First emerging as an initial access broker persona on underground cybercrime forums around mid-2024, ALP-001 transitioned in March 2026 to operating a dedicated dark web data leak site and extortion market. Operating as a financially motivated threat actor, the group sets itself apart by bridging the gap between access brokerage and direct extortion, using its established access channels to exfiltrate and monetise target files rather than relying solely on payload deployment. This operational model incorporates low-credibility or recycled data claims alongside genuine intrusions, placing significant verification burdens on targeted organisations. The group operates under its primary handle while sharing underlying contact identifiers across cybercrime forums, frequently being evaluated alongside low-fidelity extortion operations like 0APT.

IQ19 victimsFirst seen: 2024-06-01Last seen: 2026-04-08

Target Countries

United Arab EmiratesArgentinaAustriaBelgiumBrazilCanadaSwitzerlandChinaCubaCzech RepublicGermanySpainFranceUnited KingdomHungaryIsraelIndiaItalyJapanKorea, Republic ofMoroccoMartiniqueMexicoNetherlandsNew ZealandPolandSlovakiaUkraineUnited StatesKosovo

Target Sectors

Food ManufacturingOther Information ServicesSoftware PublishersAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationWholesale TradeData Processing ServicesInternet PublishingSpace & DefenseEnergy & Utilities Motion Picture and Video ProductionAll Other Information ServicesComputer Systems Design and Related ServicesPublishing ServicesAccommodation&Food ServicesMiningTelecommunicationsTransportation&WarehousingRetailAgriculture&ForestryElectrical&Electronical ManufacturingInformation ServicesComputer Design & ServicesBankingOtherFinanceProfessional&Technical ServicesHealthCare & Social AssistanceArts & EntertainmentHardware ManufacturingNational SecurityOffices of LawyersComputer Systems Design Services