Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade
ID: 77b821c8-0dd1-5e12-8c02-7b196cda6498
STIX ID: report--77b821c8-0dd1-5e12-8c02-7b196cda6498
Feed Name: The Register (Security)
Morphisec's analysis of the Cicada3301 ransomware describes a Rust-based ransomware strain with notable similarities to BlackCat/ALPHV, active since June and observed infecting at least 20 organizations (primarily SMBs in North America and the UK). The report details technical TTPs—deleting shadow copies via vssadmin, WMI and bcdedit tampering, execution via a renamed PsExec with embedded compromised credentials—evidence of EDR evasion and obfuscation, changing sample architectures, provided IoCs, and that operators solicit payment in Bitcoin and Monero while recruiting affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
