Skip to content

Cicada3301

Cicada3301 is a ransomware-as-a-service operation first observed in mid-2024.

Profile source: Mallory opens in a new tab

Cicada3301

Family profile

Cicada3301 is a ransomware-as-a-service operation first observed in mid-2024. The group deploys a Rust-based ransomware family targeting Windows, Linux, and VMware ESXi environments and operates a double-extortion model that combines file encryption with data-theft pressure through a leak site. Cicada3301 has been discussed as a possible rebrand, derivative, or code descendant of ALPHV/BlackCat, but any direct lineage remains unverified.

Technical analysis has identified substantial similarities between Cicada3301 and ALPHV, particularly in Linux and ESXi encryptors. Reported overlaps include use of Rust, ChaCha20 for file encryption with an RSA public key protecting per-file or per-session symmetric material, similar command-line options, comparable ransom-note conventions, and nearly identical logic for shutting down virtual machines and deleting snapshots on ESXi hosts. Analyses have also indicated that the Windows and ESXi builds are likely the same ransomware codebase compiled for different targets.

On Linux and ESXi, Cicada3301 has been observed as an ELF binary that accepts execution parameters controlling delay, user-interface output, VM and snapshot handling, and key validation. The malware decrypts an embedded ransom note from an encrypted blob within the binary, validates a supplied key before proceeding, generates encryption material using system randomness, encrypts smaller files fully and larger files partially, and appends encrypted keying material and a victim-specific extension to encrypted files. Its ESXi-focused behavior includes terminating virtual machine processes and removing snapshots to maximize operational impact.

Observed intrusion activity associated with Cicada3301 indicates initial access can be obtained through valid accounts, including remote access through ScreenConnect, with reporting assessing that such credentials were likely stolen or brute-forced. Some reporting links this access pattern to Brutus botnet activity associated with password-guessing against remote access and VPN services. Cicada3301 operators have also been reported seeking exploitation opportunities involving ScreenConnect vulnerabilities. Infrastructure overlap has additionally been noted between Cicada3301 affiliate activity and ShadowSyndicate-linked infrastructure, though that does not by itself establish organizational identity.

Cicada3301 has been active across multiple sectors and geographies as part of the broader ransomware ecosystem and has appeared in 2024 victim and prevalence reporting as an emerging operation. The group recruits affiliates on Russian-language cybercrime forums and fits the broader professionalized RaaS model rather than a single closed intrusion set.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Defense Evasion

  • EDRSandBlast

Discovery Enum

  • ADRecon
  • PowerView
  • SoftPerfect NetScan

Exfiltration

  • RClone

LOLBAS

  • BCDEdit
  • PsExec
  • WMIC

Networking

  • GOST
  • Plink

Offsec

  • PowerSploit
  • Rubeus

Reported operators

Threat actors

1 named in public reporting
ShadowSyndicate

We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.

Exploited software

Vulnerabilities linked to Cicada3301

2 CVEs

MITRE ATT&CK

Cicada3301 in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.