On 25 March 2024, the ALPHV/BlackCat ransomware operation effectively collapsed following an FBI seizure of its infrastructure and a deeply damaging affiliate exit scam in which the core team apparently pocketed a $22 million ransom payment from Change Healthcare without distributing affiliate shares. The operation had been one of the most technically sophisticated and prolific RaaS platforms in operation since its 2021 emergence, responsible for some of the most significant breaches in the healthcare sector’s history.
Approximately two months later, a new RaaS platform appeared. It called itself Cicada3301 — sharing a name with the famous cryptographic puzzle series that ran from 2012 to 2014 — and began advertising on dark web forums for affiliates. Its technical profile bore striking similarities to ALPHV/BlackCat: a Rust-based encryptor with Windows, Linux, and ESXi support, similar configuration options, analogous operational patterns. Palo Alto Unit 42, which began tracking the group under the name Repellent Scorpius, noted that the structural overlap was significant enough to treat the groups as closely related.
The question of whether Cicada3301 is a direct successor to ALPHV — built by former ALPHV operators reusing code or concepts — or an independent group that independently converged on a similar technical approach is unresolved. What is not in question is that Cicada3301 is an active, technically capable RaaS operation with a growing victim list and a track record of prioritising VMware ESXi environments as high-value targets.
Group Overview
| Attribute | Detail |
|---|---|
| Common names | Cicada3301, Repellent Scorpius (Unit 42) |
| First observed | May–June 2024 |
| Relationship to ALPHV | Disputed; significant technical similarities, some researchers assess successor operation |
| Platform | Ransomware-as-a-Service (RaaS) |
| Encryptor language | Rust |
| Platform support | Windows, Linux, VMware ESXi |
| Affiliate commission | 20% (exceptionally low for RaaS market) |
| Affiliate recruitment | Dark web forums; active since Q2 2024 |
| Victim data disclosure | Tor-based leak site active from launch |
| Current status | Active; expanding victim count through 2026 |
The 20% commission rate retained by the core team is unusually low by RaaS market standards — most established platforms take 20-30%, and some take more. The low rate may reflect competitive pressure from the crowded 2024 post-ALPHV ecosystem, or it may be a deliberate strategy to attract experienced, high-volume affiliates who deliver large ransoms where a lower percentage still represents significant absolute revenue.
ALPHV Connection: The Evidence
The case for an operational link between Cicada3301 and ALPHV rests on several overlapping technical and operational observations:
Rust-based encryptor with ESXi support. ALPHV/BlackCat was notable in 2021 for being the first major ransomware to be written in Rust, which at the time represented a meaningful technical differentiator. Cicada3301’s encryptor uses the same language. While Rust adoption in ransomware has grown since 2021, the combination of Rust, ESXi targeting, and the operational model overlap is significant.
Configuration file format. Researchers who analysed Cicada3301 samples noted that the encryptor’s JSON configuration structure — including field names for sleep timing, network share discovery, and file exclusion lists — closely mirrors the configuration schema documented in ALPHV samples. Independent development toward an identical structure is less parsimonious than reuse or derivation.
Operational timing. Cicada3301 appeared on affiliate recruitment forums approximately eight weeks after ALPHV’s March 2024 collapse. The timeline is consistent with former ALPHV operators rebuilding under a new brand — enough time to establish new infrastructure and recruit but not long enough for the platform to have been built from scratch post-collapse.
Initial victim patterns. Early Cicada3301 victims overlapped geographically and sectorally with ALPHV’s established targeting profile — North American and European organisations in healthcare, legal, and financial services.
Counter-evidence. No direct code lineage has been publicly established through shared binary artefacts. The similarities could reflect independent implementation of a successful operational template that was publicly documented following ALPHV’s earlier operations. Some researchers have noted differences in the encryptor’s file header format and encryption key handling that suggest modification rather than direct reuse.
The operational picture is consistent with former ALPHV core operators either directly rebuilding under a new name, or experienced ALPHV affiliates with access to the technical documentation who independently reconstructed the platform. Either interpretation produces a group with access to ALPHV’s operational knowledge.
Technical Profile
Encryptor language and compilation. The encryptor is written in Rust and compiled to native binaries for each target platform: Windows PE files, Linux ELF binaries, and VMware ESXi-specific Linux builds. Rust’s safety guarantees and performance characteristics have made it attractive for ransomware development — statically linked binaries reduce dependency concerns, and the language’s ownership model helps avoid common memory management bugs that can cause operational failures during deployment.
Encryption scheme. Cicada3301 uses ChaCha20 for file content encryption combined with RSA-OAEP for key encapsulation. ChaCha20 is a modern stream cipher favoured for speed and security over AES-CTR in environments without hardware AES acceleration. Each encrypted file receives a per-file ChaCha20 key encrypted with an embedded RSA-4096 public key. The session’s private key is held by the operators, making decryption without payment infeasible.
Intermittent encryption. For large files, Cicada3301 implements intermittent encryption — encrypting the first N bytes plus periodic intervals through the file rather than the entire content. This significantly reduces encryption time and allows the encryptor to process a larger number of files before being detected, at the cost of partial file corruption rather than complete encryption. The result is that affected files cannot be used even if they are not completely encrypted. This pattern was previously used by ALPHV and is now common among technically mature RaaS encryptors.
File extension. Encrypted files receive a randomly generated six-character alphanumeric extension appended to the original filename. The extension is unique per victim (generated from the configuration) and included in the ransom note to allow victims to confirm they are dealing with the correct group.
VMware ESXi targeting. The ESXi build includes specific logic for enumerating and stopping running virtual machines before encryption — preventing file locking that would prevent the encryptor from accessing VMDK files. The sequence: authenticate to ESXi, enumerate running VMs via esxcli, stop each VM, then encrypt the underlying VMDK files and associated configuration. This approach, which targets virtualisation infrastructure directly rather than individual guest operating systems, allows a single ESXi host compromise to effectively encrypt multiple production servers simultaneously.
Windows shadow copy deletion. On Windows targets, the encryptor executes VSS deletion via vssadmin.exe delete shadows /all /quiet and via WMI queries, removing the most common low-cost recovery mechanism for SMB environments.
Network share discovery. The encryptor includes logic to enumerate network shares visible to the compromised host and extend encryption to mapped drives and accessible UNC paths. This allows a single encryptor execution to affect data on file servers beyond the directly compromised system.
Ransom note. A text file is dropped in each encrypted directory. The note includes a unique victim ID, a Tor onion address for the negotiation portal, and a claim that data has been exfiltrated to the leak site pending payment. Notes observed in Cicada3301 incidents are formatted similarly to late-period ALPHV notes.
Affiliate Model and Operations
Cicada3301’s affiliate programme, as advertised on dark web forums, offers:
- 20% commission to the core team, 80% to the affiliate
- Access to the Cicada3301 affiliate panel: victim management, encryptor build configuration, ransom negotiation infrastructure
- Data exfiltration infrastructure and leak site management handled by the core team
- Technical support for affiliates during operations
- Custom encryptor builds configurable per engagement (target extensions, network share scope, sleep parameters, ransom note text)
The affiliate panel has been described by researchers with access to leaked screenshots as a modern web application with a dashboard interface — consistent with the standard of professionalism expected in the post-LockBit RaaS market. The panel allows affiliates to track victim negotiation status, generate custom builds, and manage communication.
Cicada3301 recruits affiliates with demonstrated experience — they advertise for actors with prior RaaS experience or established access to high-value corporate networks. They specifically recruit English-speaking affiliates with access to North American and European targets, and Russian-speaking affiliates with established criminal network connections.
Targeting and Victims
Cicada3301’s victim profile is broadly consistent with the mid-market segment that RaaS affiliates typically prefer: organisations large enough to pay meaningful ransoms but without the incident response resources of large enterprises.
Sectors represented in claimed victims include:
- Healthcare: outpatient care groups, specialty clinics, pharmaceutical distribution
- Legal and professional services: law firms, accounting practices
- Manufacturing: industrial suppliers, electronics manufacturers
- Technology: IT services companies, managed service providers
- Finance: regional financial services organisations
Geographically, victims are concentrated in North America (United States and Canada) and Western Europe (UK, Germany, France, Italy). The group has also claimed victims in Japan and Australia.
Victim count has grown through 2024 into 2025 and 2026, reflecting successful affiliate recruitment and ongoing operations. Cicada3301 is not among the highest-volume groups in the ecosystem — the group appears to prioritise quality of targeting over volume — but its claimed victims include organisations where reported ransom demands have been in the seven-figure range.
Post-Intrusion TTPs
Cicada3301 affiliate operations follow the standard advanced ransomware affiliate playbook with some specific procedural patterns:
Initial access. No single consistent initial access method is documented. Observed entry points include: VPN credential abuse (particularly against Cisco ASA and Fortinet appliances where CVEs are exploitable or credentials have been purchased), phishing with subsequent credential harvesting, and exploitation of internet-facing services. Several incidents involved initial access broker purchases of established remote access sessions.
Credential access. LSASS process dump using ProcDump or comsvcs.dll, Mimikatz for credential parsing, Active Directory credential extraction (DCSync where domain admin is obtained), and credential extraction from browser stores.
Discovery. Active Directory enumeration via ADFind or SharpHound. Network mapping via internal tools. ESXi host discovery via network scanning. Identification of backup infrastructure and file servers.
Lateral movement. PsExec for remote execution, RDP for manual access to administration interfaces, WMI for command execution across systems.
Persistence. Scheduled task creation, service installation, and domain account manipulation. Persistence is maintained through the exfiltration phase, which may run for multiple days.
Exfiltration. Data theft using rclone, configured to exfiltrate to Mega.nz or attacker-controlled cloud endpoints. Exfiltration targets business-critical data: financial records, customer data, intellectual property, HR records. The exfiltration payload informs the data listed on the leak site under the victim’s entry.
Execution. Encryptor deployment via PsExec or Group Policy. ESXi compromise handled through direct administrative access or via management host compromise.
Resilience and Ecosystem Significance
Cicada3301’s emergence illustrates a structural dynamic in the ransomware ecosystem that has become more pronounced since 2022: successful RaaS operations generate technical knowledge, operational experience, and criminal network relationships that persist beyond the platform itself.
When ALPHV collapsed, the individuals and relationships involved did not disappear. They regrouped, rebuilt, and resumed operations under a new name with infrastructure that deliberately obscured the connection to the prior operation. Law enforcement action against RaaS core teams — however justified and valuable — faces this structural reality: the knowledge required to operate at this level is distributed across the affiliate community and is not eliminated by taking down a single server cluster or arresting a subset of the core team.
For defenders, Cicada3301 represents a continuation of the ALPHV threat model: technically capable, professionally operated, with a specific focus on virtualised infrastructure that allows single-host compromises to encrypt production server estates. The ESXi targeting in particular reflects strategic awareness of where modern enterprise infrastructure runs and how to maximise impact per intrusion.
Defensive Implications
Protect ESXi management interfaces. ESXi hosts should not have management interfaces exposed to the enterprise LAN without compensating controls. Restrict ESXi management access to dedicated, monitored management hosts. Require MFA for ESXi administrative access. Maintain separate credentials for ESXi administration that are not stored in the domain or reusable from compromised Windows systems.
Backup ESXi infrastructure independently. VMware-level backups (VMDK snapshots) should be stored to immutable storage outside the VMware environment. Backups accessible from ESXi management credentials are a target during ransomware operations.
Patch perimeter VPN appliances promptly. Cisco ASA and Fortinet FortiGate vulnerabilities are recurring initial access vectors for Cicada3301 affiliates. Treat these appliances with the same urgency as public-facing web applications.
MFA on all remote access. VPN, RDP, Citrix, and remote desktop gateway should all require phishing-resistant MFA. Credential theft from initial access broker purchases is less useful when credentials require a second factor tied to a physical device.
Monitor for LSASS access. Windows Event ID 10 (process access to lsass.exe) via Sysmon, or EDR telemetry showing unusual process handle requests to lsass.exe, provides early detection of credential dumping activities in the post-intrusion phase.
Network segmentation between IT and virtualisation infrastructure. ESXi management networks should not be reachable from general enterprise segments. Lateral movement from a compromised workstation to ESXi management infrastructure requires network connectivity that should not exist by default.
Cicada3301/Repellent Scorpius is a first-tier RaaS threat. Its technical quality, ESXi focus, and likely lineage to ALPHV expertise make it one of the more capable affiliate platforms currently operating. Organisations with significant VMware infrastructure in sectors historically targeted by ALPHV — healthcare, legal, financial services — should treat this group as a current and credible threat.