Cicada3301 is a ransomware-as-a-service operation first observed in mid-2024. The group deploys a Rust-based ransomware family targeting Windows, Linux, and VMware ESXi environments and operates a double-extortion model that combines file encryption with data-theft pressure through a leak site. Cicada3301 has been discussed as a possible rebrand, derivative, or code descendant of ALPHV/BlackCat, but any direct lineage remains unverified.
Technical analysis has identified substantial similarities between Cicada3301 and ALPHV, particularly in Linux and ESXi encryptors. Reported overlaps include use of Rust, ChaCha20 for file encryption with an RSA public key protecting per-file or per-session symmetric material, similar command-line options, comparable ransom-note conventions, and nearly identical logic for shutting down virtual machines and deleting snapshots on ESXi hosts. Analyses have also indicated that the Windows and ESXi builds are likely the same ransomware codebase compiled for different targets.
On Linux and ESXi, Cicada3301 has been observed as an ELF binary that accepts execution parameters controlling delay, user-interface output, VM and snapshot handling, and key validation. The malware decrypts an embedded ransom note from an encrypted blob within the binary, validates a supplied key before proceeding, generates encryption material using system randomness, encrypts smaller files fully and larger files partially, and appends encrypted keying material and a victim-specific extension to encrypted files. Its ESXi-focused behavior includes terminating virtual machine processes and removing snapshots to maximize operational impact.
Observed intrusion activity associated with Cicada3301 indicates initial access can be obtained through valid accounts, including remote access through ScreenConnect, with reporting assessing that such credentials were likely stolen or brute-forced. Some reporting links this access pattern to Brutus botnet activity associated with password-guessing against remote access and VPN services. Cicada3301 operators have also been reported seeking exploitation opportunities involving ScreenConnect vulnerabilities. Infrastructure overlap has additionally been noted between Cicada3301 affiliate activity and ShadowSyndicate-linked infrastructure, though that does not by itself establish organizational identity.
Cicada3301 has been active across multiple sectors and geographies as part of the broader ransomware ecosystem and has appeared in 2024 victim and prevalence reporting as an emerging operation. The group recruits affiliates on Russian-language cybercrime forums and fits the broader professionalized RaaS model rather than a single closed intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The files will then be encrypted with a symmetric key generated by OsRng using ChaCha20. | If it is greater than 0x6400000, then it will encrypt the file in parts, and if it is smaller, the whole file will be encrypted.
Both use almost identical commands to shutdown VM and remove snapshots... esxcli vm process kill –type=force –world-id=
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cicada3301 is a ransomware group responsible for at least two incidents in Japan in the first half of 2025.
Ransomware operation referenced as active in Q2 2025 (no additional detail provided).
Rust-based ransomware-as-a-service first observed in June 2024; discussed as potentially a BlackCat/ALPHV rebrand and linked to ScreenConnect exploitation and overlapping infrastructure with ShadowSyndicate.
A ransomware group analyzed as another possible BlackCat rebrand. The content emphasizes strong code similarities with BlackCat, especially in ESXi variants, but says evidence is still insufficient for high-confidence attribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.