Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors cicada3301

Description

Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions. Known victims: 75 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Cicada3301, also tracked as Repellent Scorpius by Palo Alto Networks, is a ransomware-as-a-service (RaaS) group suspected to be linked to BlackCat/ALPHV. This threat actor emerged in mid-2024 and operates with medium sophistication, targeting Windows, Linux, and ESXi systems using Rust-based ransomware. Primary motivations include organizational gain and financial profit throughransom payments.

Goals & Targeting

The group's strategic objectives center on maximizing financial gain through ransomware operations. They target sectors with high data sensitivity and recovery costs, such as healthcare,制造业, and critical infrastructure. The choice of Linux and ESXi systems suggests an emphasis on lateral movement and operational persistence within enterprise environments. Their geographic reach appears geographically dispersed, though early victims have been concentrated in English-speaking regions.

Enhanced Description

Cicada3301 represents a new iteration of ransomware operators leveraging RaaS models to expand their reach and profitability. The group operates with a structured affiliate program offering 20% commissions, indicating a sophisticated business model similar to predecessors like BlackCat/ALPHV. The use of Rust-based binaries signals an attempt to differentiate from traditional competitors while maintaining effective encryption capabilities. Initial Targeting focuses on identifying potential high-value assets through reconnaissance and lateral movement within networks. Cicada3301 employs double extortion tactics, encrypting data and threatening泄露 unless ransoms are paid. Notable for its rapid operational tempo and ability to adapt to defensive measures, Cicada3301 has already demonstrated significant disruptive impact on targeted organizations.

Key Capabilities

  • Ransomware encryption using Rust binaries
  • Affiliate program for recruitment
  • Double extortion tactics
  • Cross-platform targeting
  • High-speed decryption and data exfiltration

MITRE ATT&CK Tactics

Credential Access
Defense Evasion
Data Exfiltration
Lateral Movement
Persistence

ATT&CK Techniques

T1078.001 - Account Access Removal:credential dumping via mimikatz
T1685.004 - Data Exfiltration:ransomware encryption of data on endpoints
T839.002 - OSQuery for persistent reconnaissance and lateral movement
T1270.001 - Ransomware Deployment via Remote Desktop Protocol
T1185.001 - Web Shell Usage for Lateral Movement

Software / Tooling

Cobalt Strike
Mimikatz
OsQuery
Custom-built ransomware binaries
Doppelgängerkultur2.0 ransom note generator

Campaigns & Victims

Cicada3301's campaigns are characterized by high-speed execution and use of double extortion tactics. Victims have included healthcare providers, manufacturing firms, and financial institutions. Their affiliate program indicates an intent to scale operations rapidly, potentially leading to increased attack volume. Notable for their sophisticated TTPs, they frequently combine phishing with lateral movement techniques and web shell-based exfiltration.

IOC Patterns

  • Spear-phishing emails containing malicious links or attachments
  • Ransomware encryption of files with appended .cicada or .scorpius extensions
  • Use of Doppelgängerkultur2.0 ransom notes in German
  • Network traffic anomalies indicative of web shell usage
  • Credential dumping via mimikatz on compromised systems

Recommended Actions

  • Implement multi-factor authentication (MFA) for sensitive accounts
  • Monitor network logs for unusual web requests characteristic of C2 servers
  • Segment critical business units from general network access
  • Conduct regular backups and ensure air-gapped storage solutions
  • Provide user training on identifying phishing attempts and suspicious emails

Suggested Tags

ransomware
affiliate-program
financial-gain
cross-platform-targeting
linux-malware
esxi-malware

Confidence Assessment

Moderate confidence level in complete TTPs and actor attributions due to limited operational history and emerging nature of the group. Potential gaps exist in understanding their long-term strategic goals and precise targeting criteria beyond observed patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
affiliate-program
financial-gain
cross-platform-targeting
linux-malware
esxi-malware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 4, 2024
Last Seen
Sep 4, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.