Cicada3301 is a financially motivated ransomware-as-a-service operation first observed in June 2024. It operates a double-extortion model, providing affiliates with ransomware and using a dedicated leak site to pressure victims through threatened publication of stolen data. The operation recruited affiliates on Russian-language cybercrime forums. Cicada3301 deploys Rust-based ransomware against Windows and Linux/VMware ESXi environments. Its encryptors use ChaCha20 for file encryption and RSA public-key cryptography to protect generated symmetric keys. The ESXi variant can terminate virtual machines and remove snapshots before encryption, supports partial encryption of large files, and includes execution-delay and progress-display options. Analysis identified substantial technical similarities with ALPHV/BlackCat, including Rust implementation, encryption design, ESXi virtual-machine shutdown and snapshot-removal behavior, and ransom-note conventions. These overlaps support possible code reuse, shared development, or a relationship with ALPHV, but do not establish Cicada3301 as a definitive ALPHV rebrand. Observed intrusion activity associated with Cicada3301 has included use of valid credentials through ScreenConnect, with credentials assessed as potentially stolen or obtained through password guessing. The group has been linked to attacks against healthcare entities and has been reported as active against organizations in Japan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with healthcare-sector dedicated leak-site postings.
Cicada3301 is a ransomware group responsible for two incidents in Japan in the first half of 2025.
A recent RaaS program whose affiliate infrastructure overlaps with ShadowSyndicate, including exfiltration infrastructure and possible ties to ALPHV/BlackCat rebranding theories.
RaaS/extortion group claiming very large data exfiltration against a life sciences testing company.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.