logo

Sicarii Ransomware: Truth vs Myth

ID: fd5fca68-ad52-5ae5-a8aa-57fd038a3fb0

STIX ID: report--fd5fca68-ad52-5ae5-a8aa-57fd038a3fb0

Feed Name: Check Point Research

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Sicarii RaaS overview:** Sicarii is a recently observed ransomware-as-a-service operation that combines functional extortion capabilities (AES-GCM per-file encryption with the .sicarii extension, data exfiltration via file.io, LSASS dumping, persistence, and a destructive boot-stage) with unusual Israeli/Jewish branding and geo-fencing logic to avoid Israeli systems; linguistic and behavioral anomalies raise the possibility of performative identity or false-flag activity rather than a mature ideologically-driven campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.