Defense Evasion
- EDRSandBlast
Cicada3301 is a ransomware-as-a-service operation first observed in mid-2024.
Profile source: Mallory opens in a new tabCicada3301
Cicada3301 is a ransomware-as-a-service operation first observed in mid-2024. The group deploys a Rust-based ransomware family targeting Windows, Linux, and VMware ESXi environments and operates a double-extortion model that combines file encryption with data-theft pressure through a leak site. Cicada3301 has been discussed as a possible rebrand, derivative, or code descendant of ALPHV/BlackCat, but any direct lineage remains unverified.
Technical analysis has identified substantial similarities between Cicada3301 and ALPHV, particularly in Linux and ESXi encryptors. Reported overlaps include use of Rust, ChaCha20 for file encryption with an RSA public key protecting per-file or per-session symmetric material, similar command-line options, comparable ransom-note conventions, and nearly identical logic for shutting down virtual machines and deleting snapshots on ESXi hosts. Analyses have also indicated that the Windows and ESXi builds are likely the same ransomware codebase compiled for different targets.
On Linux and ESXi, Cicada3301 has been observed as an ELF binary that accepts execution parameters controlling delay, user-interface output, VM and snapshot handling, and key validation. The malware decrypts an embedded ransom note from an encrypted blob within the binary, validates a supplied key before proceeding, generates encryption material using system randomness, encrypts smaller files fully and larger files partially, and appends encrypted keying material and a victim-specific extension to encrypted files. Its ESXi-focused behavior includes terminating virtual machine processes and removing snapshots to maximize operational impact.
Observed intrusion activity associated with Cicada3301 indicates initial access can be obtained through valid accounts, including remote access through ScreenConnect, with reporting assessing that such credentials were likely stolen or brute-forced. Some reporting links this access pattern to Brutus botnet activity associated with password-guessing against remote access and VPN services. Cicada3301 operators have also been reported seeking exploitation opportunities involving ScreenConnect vulnerabilities. Infrastructure overlap has additionally been noted between Cicada3301 affiliate activity and ShadowSyndicate-linked infrastructure, though that does not by itself establish organizational identity.
Cicada3301 has been active across multiple sectors and geographies as part of the broader ransomware ecosystem and has appeared in 2024 victim and prevalence reporting as an emerging operation. The group recruits affiliates on Russian-language cybercrime forums and fits the broader professionalized RaaS model rather than a single closed intrusion set.
Reported operators
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.