Sicarii is a ransomware-as-a-service operation that emerged in late 2025. It presents itself as an Israeli or Jewish-aligned group, using Hebrew language, Israeli symbolism, and historical references in its branding, but multiple assessments indicate this persona is likely a false-flag or performative identity. The group’s underground activity, affiliate recruitment, and operator communications are primarily conducted in Russian, and its Hebrew content has been assessed as non-native or machine-translated. Available reporting therefore points more strongly to Russian-speaking operators than to genuine Israeli affiliation. Operationally, Sicarii is a functional but immature and unusually centralized RaaS operation. It has advertised for affiliates on underground forums and later experienced a surge in affiliate interest significant enough that its administrator redirected operators toward Baqiyat 313 Locker (BQTlock), while indicating an intent to focus more on hacktivist influence. Sicarii has also been described as part of a broader pro-Iranian and pro-Palestinian ransomware ecosystem in which operators encouraged widespread victimization, particularly in the Middle East, Turkey, and Africa region. Sicarii combines ransomware with extensive pre-encryption collection and destructive behavior. Reported capabilities include anti-virtualization and sandbox evasion, geo-fencing to avoid execution on Israeli systems, system and network reconnaissance, credential theft, keylogging, browser and application data theft, exfiltration of collected data, persistence through service and account creation, and lateral movement activity including exploitation of Fortinet devices. The malware encrypts files using AES-GCM and appends a dedicated extension, while also deploying a destructive startup script intended to corrupt boot components and wipe disks. This combination makes Sicarii closer to destructive pseudo-ransomware in some incidents than to conventional profit-driven ransomware. A defining characteristic of Sicarii is a severe cryptographic design flaw: the malware generates fresh key material during execution and discards the corresponding private key, making decryption impossible for victims and, in practice, for the operators as well. This defect means ransom payment may not restore data and has led researchers to characterize Sicarii as effectively destructive malware masquerading as ransomware. Some assessments further suggest AI-assisted development may have contributed to the poor implementation quality. Sicarii has been associated with data theft and extortion claims, but reporting also notes inconsistencies in its public statements and victim narratives. Overall, Sicarii is best understood as an emerging, technically uneven RaaS actor with Russian-speaking operators, false-flag Israeli/Jewish branding, destructive tendencies, and a flawed encryption model that undermines any credible promise of recovery.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operators whose encryption implementation deleted the private key after generation, making decryption impossible even after payment.
A newer ransomware-as-a-service operation notable for poorly implemented malware that discards the private key during execution, making decryption unreliable or impossible and turning attacks into effectively destructive incidents.
A ransomware operation whose administrator encouraged pro-Iranian operators to use BQTlock amid increased affiliate demand.
Pseudo-ransomware actor focused on destructive wiping rather than monetization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.