Cicada3301
Ransomware-as-a-Service (RaaS) — ALPHV/BlackCat successor (assessed) · Financial — ransomware and extortion
Tactics, Techniques & Procedures (TTPs)
- Rust-based cross-platform encryptor with strong technical and code-level similarities to ALPHV/BlackCat
- ChaCha20 encryption with RSA-OAEP key encapsulation — same construction as ALPHV
- Intermittent encryption for large files: accelerates completion, reduces detection window before encryption is complete
- VMware ESXi specialist — enumerates VMs via esxcli/vim-cmd, terminates workloads, encrypts VMDK files
- Configurable per-victim encryption parameters and file extension via affiliate builder
- Initial access via VPN credential theft and exposed remote services
- 20% core team commission / 80% affiliate split — standard major RaaS structure
Known Targets
Analyst Notes
Cicada3301 (Repellent Scorpius, Unit 42) emerged May 2024 — two months after the ALPHV/BlackCat collapse. The technical similarities are significant: both written in Rust, both use ChaCha20+RSA-OAEP encryption, near-identical ESXi targeting logic, and similar configuration file structures. Unit 42 assessed Cicada3301 as either a direct successor or a group with access to ALPHV source code or a significant ALPHV developer. ESXi targeting remains the most operationally significant capability — a single ESXi host compromise can encrypt dozens of virtual servers simultaneously.
Also Known As