Skip to main content
Mallory
MalwareRansomware

Sicarii

Sicarii is a ransomware-as-a-service (RaaS) operation first observed in late 2025 / December 2025. It is a functional ransomware threat with extortion, data theft, reconnaissance, persistence, and destructive capabilities, but multiple reports describe it as immature and operationally anomalous. Check Point assessed that Sicarii presents itself as an Israeli/Jewish operation using Hebrew language, historical symbols, and ideological references, while much of its underground activity and affiliate recruitment is conducted in Russian; the Hebrew content reportedly appears machine-translated or non-native, suggesting likely false-flag or performative identity signaling. Sicarii has also been described in reporting as being used by pro-Iranian or pro-Palestinian aligned operators in the broader Middle East ecosystem, and Halcyon reported that in March 2026 its administrator redirected operators toward Baqiyat 313 Locker (BQTlock) due to affiliate demand.

Technically, Sicarii encrypts files using AES-GCM / AES-256-GCM and appends the .sicarii extension. The malware has been reported to generate a new RSA key pair during execution and then discard the private key, a critical cryptographic flaw that makes decryption permanently impossible for victims and operators alike and renders ransom payment futile. This key-handling defect is one of the most consistently reported characteristics of the malware.

Reported behavior includes anti-virtualization / sandbox checks, single-instance execution via mutex, copying itself to a temp directory under an svchost-like randomized filename, and repeated connectivity checks to google.com/generate_204. Sicarii performs host and network reconnaissance, including ARP-based discovery and scanning for exposed RDP services. It steals data including system credentials, browser data, registry hives, and application data from services such as Discord, Slack, Telegram, WhatsApp, Office, Roblox, and Atomic Wallet; some reporting also mentions cryptocurrency wallet theft generally. Stolen data is packaged into collected_data.zip and exfiltrated via file.io. Persistence mechanisms reported include registry Run keys, service creation, and creation of local user accounts with hardcoded credentials such as SysAdmin / Password123!. Some reporting also states it attempts to create a new AWS user without checking whether AWS is installed.

For lateral movement or follow-on compromise, Sicarii has been associated with exploitation of Fortinet devices, including references to CVE-2025-64446. It also includes geo-fencing intended to avoid execution on Israeli systems by checking time zone, keyboard layout, and Israeli IP indicators. A destructive component has been reported as well: startup batch scripts such as destruct.bat that corrupt bootloader files, invoke disk-wiping related commands, and force immediate shutdown.

Targeting reporting is mixed but consistently places Sicarii in the Middle East, Turkey, and Africa region, with at least one reported US-based victim. Check Point reporting also cited operator claims of targeting small businesses. Known high-confidence indicators directly mentioned in the content include the .sicarii file extension, collected_data.zip, exfiltration via file.io, temp-file naming in the form svchost_{random}.exe, the WinDefender service name, the SysAdmin account with password Password123!, and connectivity checks to google.com/generate_204.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

T1189Drive-by CompromiseEvidence1

вредоносной рекламы, веб-инжектов

T1566PhishingEvidence1

с помощью email-спама и вредоносных вложений

Execution

2 techniques
T1203Exploitation for Client ExecutionEvidence1

эксплойтов

T1204.002Malicious FileEvidence1

обманных загрузок, ботнетов, эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений, перепакованных и заражённых инсталляторов

Persistence

1 technique
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

Сетевые подключения и связи: Tor-URL: sicariifoucvhyqg54smi3esg5sfcyw5z65t6yigqu4loyuoz62bb2id.onion ...

Impact

2 techniques
T1485Data DestructionEvidence1

Deploying ransomware before wiping an organization’s data and/or using destructionware, or destructive malware, that render system recovery impossible

T1486Data Encrypted for ImpactEvidence4

Nova, the affiliate program for ransomware crew RAlord, on Tuesday issued an apology to Eriell Group... The malware slingers claimed they didn’t encrypt any files... Pro-Russian hacktivist crew CyberVolk got sloppy when they debuted a ransomware service late last year. They hardcoded the master keys... thus allowing victims to recover encrypted data without paying any extortion fees. ... Sicarii encryptor generates a new cryptographic key pair during every execution... Similarly, a programming mistake in Nitrogen ransomware prevents the gang's decryptor from recovering victims' files

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.