Sicarii Ransomware Masquerades as Israeli Hacktivists
ID: 722bc8dd-e4ce-5828-82a1-639a0f1c6e1b
STIX ID: report--722bc8dd-e4ce-5828-82a1-639a0f1c6e1b
Feed Name: securityonline.info
Check Point's analysis finds Sicarii to be a Ransomware-as-a-Service operation that adopts Israeli/Jewish branding likely as a false flag while its activity and recruitment are primarily conducted in Russian. The group is operationally capable — performing data exfiltration, credential harvesting, exploiting Fortinet vulnerabilities, and encrypting files with AES-GCM using a .sicarii extension — but is described as centralized, informal, and early-stage rather than a mature cartel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
