logo

BlackCat Spin-off 'Cicada3301' Uses Stolen Creds on the Fly, Skirts EDR

ID: 58c49323-8916-56dc-b76c-b0923da68b96

STIX ID: report--58c49323-8916-56dc-b76c-b0923da68b96

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-09-03

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Cicada3301 is a Rust-based, BlackCat-like ransomware operation reported to have compromised 21 organizations across Europe and North America; it offers customizable encryption options, uses stolen credentials with PsExec for lateral movement, leverages EDR bypass tooling, and has rapidly improved obfuscation to evade antivirus detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.