logo

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

ID: 77b821c8-0dd1-5e12-8c02-7b196cda6498

STIX ID: report--77b821c8-0dd1-5e12-8c02-7b196cda6498

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-09-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Morphisec's analysis of the Cicada3301 ransomware describes a Rust-based ransomware strain with notable similarities to BlackCat/ALPHV, active since June and observed infecting at least 20 organizations (primarily SMBs in North America and the UK). The report details technical TTPs—deleting shadow copies via vssadmin, WMI and bcdedit tampering, execution via a renamed PsExec with embedded compromised credentials—evidence of EDR evasion and obfuscation, changing sample architectures, provided IoCs, and that operators solicit payment in Bitcoin and Monero while recruiting affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.