Researchers at Halcyon’s Ransomware Research Center (RRC) reported that the emerging Sicarii ransomware has a critical implementation flaw that prevents successful decryption, even if victims pay. Sicarii is being promoted as a ransomware-as-a-service (RaaS) offering on underground forums, but Halcyon’s analysis indicates its encryption design is fundamentally unrecoverable, making it an unusually destructive threat compared with typical ransomware where decryption is at least theoretically possible.
The issue stems from RSA key mishandling: on execution, the malware generates a fresh RSA key pair locally, uses it to encrypt data, and then discards the private key, meaning encryption is not linked to any recoverable master key. As a result, victims have no viable decryption path and attacker-supplied decryptors are ineffective; Halcyon explicitly advised organizations not to pay a Sicarii ransom because payment cannot improve recovery outcomes. Both reports note Halcyon’s assessment that the defect may reflect low-skill development and possible over-reliance on AI-assisted “vibe coding,” and one report highlights Sicarii’s “Hebrew” branding as potentially a false flag rather than a reliable attribution signal.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Following publication of the technical analysis, researchers and incident responders advised organizations affected by Sicarii to avoid assuming payment will restore data and instead prioritize backups, isolation, forensics, scoping, and experienced incident-response support. Halcyon noted that decryption failures this severe are rare in ransomware operations.
Check Point Research found that although Sicarii presents itself with Hebrew language, Jewish symbols, and an Israeli persona, its operational activity is primarily in Russian and the Hebrew content appears machine-translated. This raised the possibility that the branding is a false-flag identity rather than a genuine attribution signal.
Halcyon’s Ransomware Research Center reported that the emerging Sicarii ransomware generates a new RSA key pair on each execution, encrypts files, and discards the private key, making attacker-supplied decryptors ineffective. The finding means victims may be unable to recover encrypted data even if they pay a ransom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.