logo

Sicarii Ransomware Masquerades as Israeli Hacktivists

ID: 722bc8dd-e4ce-5828-82a1-639a0f1c6e1b

STIX ID: report--722bc8dd-e4ce-5828-82a1-639a0f1c6e1b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Check Point's analysis finds Sicarii to be a Ransomware-as-a-Service operation that adopts Israeli/Jewish branding likely as a false flag while its activity and recruitment are primarily conducted in Russian. The group is operationally capable — performing data exfiltration, credential harvesting, exploiting Fortinet vulnerabilities, and encrypting files with AES-GCM using a .sicarii extension — but is described as centralized, informal, and early-stage rather than a mature cartel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.