Sicarii, a newly observed ransomware-as-a-service (RaaS) operation that surfaced in late 2025, has drawn attention for unusually explicit Israel/Jewish-themed branding and malware behavior that appears designed to avoid Israeli targets. Reporting indicates the group claims to focus on organizations in Arab and Muslim countries while implementing geo-fencing checks (e.g., time zone, keyboard layout, and IP-based indicators) to prevent execution on systems identified as Israeli—an uncommon choice for financially motivated ransomware and one that reduces plausible deniability. Check Point notes Sicarii has publicly claimed only one victim so far, and that its underground activity is largely conducted in Russian, while the Hebrew content appears error-prone and potentially machine-translated, raising the possibility of identity manipulation or influence-oriented signaling rather than a mature criminal operation.
Technical analysis describes Sicarii’s execution flow as including anti-analysis/anti-virtualization behavior, staging itself under a temporary-path filename like svchost_{random}.exe, and performing connectivity checks (e.g., repeated requests to google.com/generate_204) before conducting aggressive network reconnaissance. Check Point further attributes capabilities including data exfiltration, credential and network information collection, and attempts to exploit Fortinet devices, with file encryption reported as AES-GCM and appending the .sicarii extension. Separate reporting on DragonForce ransomware (including a decryptor for Windows/ESXi) is unrelated to Sicarii and does not describe the same operation or incident.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
On January 14, 2026, Check Point Research published an assessment concluding Sicarii had real extortion capability but showed anomalies suggesting immaturity, centralized development, or possible false-flag signaling. The report noted Russian- and English-language underground activity, non-native or machine-translated Hebrew, low OpSec, and inconclusive attribution.
Analysis revealed the malware used anti-VM checks, internet connectivity tests, reconnaissance, RDP scanning, data theft, and persistence mechanisms before encrypting files with the .sicarii extension. Researchers also found lateral movement attempts exploiting Fortinet devices via CVE-2025-64446 and a destructive component that could corrupt boot files and wipe disks.
By late 2025 or early 2026, Sicarii had publicly listed a Greece-based manufacturer as its first claimed victim. The operator later described this victim as 'just a test,' creating inconsistencies around the group’s claims and maturity.
In late December 2025, Sicari/Sicarii ransomware activity was observed and documented as a low-prevalence crypto-ransomware family using AES and RSA encryption against business users. The report identified artifacts including the README_SICARII_LOCKED.txt ransom note, sicarii_wallpaper.bmp, sample filenames, Tor onion payment sites, and associated file hashes.
As the operation emerged, Sicarii claimed it would target organizations in Arab and Muslim countries while avoiding Israeli systems. Its malware implemented geo-fencing checks based on time zone, Hebrew keyboard layout, and Israeli IP ranges to prevent execution on Israeli hosts.
In December 2025, a new ransomware-as-a-service operation called Sicarii appeared on underground forums and channels. It presented itself with explicit Israeli/Jewish branding, Hebrew language, and ideological symbolism.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceresearch.checkpoint.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.