Sicarii Ransomware is a newly observed ransomware-as-a-service (RaaS) operation active since late 2025. Based on the provided reporting, it targets Windows environments and encrypts victim files using AES-GCM, appending the ".sicarii" extension. During execution it drops a ransom note named "HOW_TO_RECOVER_DATA.html" and modifies the desktop wallpaper. The malware is also described as collecting system, credential, and network information, packaging and exfiltrating data prior to encryption, and supporting double-extortion by threatening to publish stolen data. Reported credential-access and surveillance capabilities include OS credential dumping and keylogging. Defense-evasion and system-modification behavior mentioned in the content includes disabling Windows Firewall, modifying registry keys under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 and related paths, use of WMI and command/scripting interpreters, access token manipulation, and creation/modification of system processes. A notable destructive component is a startup batch script named "destruct.bat," described as corrupting bootloader components and performing disk-wiping operations. The reporting characterizes the operation as functional but immature, notes inconsistencies in the operators' public claims, and states there is no publicly available decryptor. High-confidence indicators and artifacts directly mentioned in the content include the ".sicarii" file extension, the ransom note "HOW_TO_RECOVER_DATA.html," and the destructive script "destruct.bat."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
“The following are the TTPs based on the MITRE Attack Framework … Execution T1047 Windows Management Instrumentation”
“Privilege Escalation T1134 Access Token Manipulation” and “Defense Evasion T1134 Access Token Manipulation” (Sicarii).
“Persistence T1543 Create or Modify System Process” and also listed under Privilege Escalation for Sicarii.
“Defense Evasion T1027 Obfuscated Files or Information” with sub-techniques “T1027.002 … Software Packing” and “T1027.005 … Indicator Removal from Tools” (Sicarii).
“Defense Evasion T1036 Masquerading” (Sicarii) and multiple Lazarus masquerading sub-techniques are listed.
“Discovery T1057 Process Discovery” (Sicarii) and also listed for Lazarus.
“Discovery T1082 System Information Discovery” (Sicarii) and also listed for Lazarus.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation active since late 2025 that performs reconnaissance, credential/system/network data collection, data staging/packaging and exfiltration prior to encrypting files (AES-GCM) and appending the .sicarii extension; drops a ransom note (HOW_TO_RECOVER_DATA.html), changes wallpaper, and deploys a destructive startup batch script (destruct.bat) intended to corrupt boot components and wipe disks to increase coercion.
Next:Sicarii Ransomware Masquerades as Israeli Hacktivists
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.