Cicada3301 Ransomware

Description Summary

Rust RaaS with strong ALPHV/BlackCat overlap; assessed possible rebrand/successor.

Threat Actor

Assessed possible ALPHV rebrand, partnership, or modified-code successor; RAMP-advertised RaaS.

Technical Indicators

Encryption Extension
Not publicly reported
Encryption Algorithm
ChaCha20 (Rust; Windows + Linux/ESXi) — strong ALPHV/BlackCat command/file-naming overlap
Ransom Note Name
Not publicly reported
Targeted Industries
SMBs across construction, IT, legal, retail, healthcare, transport, telecom, hospitality, finance, real estate, manufacturing
First Seen
June 2024
Last Seen
Active
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts