Cicada3301 ransomware’s Linux encryptor targets VMware ESXi systems
ID: 2b5ff0dd-0054-55af-ab92-746d14ce9bd4
STIX ID: report--2b5ff0dd-0054-55af-ab92-746d14ce9bd4
Feed Name: Bleeping Computer
A new RaaS operation calling itself Cicada3301 — unaffiliated with the original Cicada 3301 project — has been active since early June, using double-extortion tactics and listing victims on an extortion site. Analysis shows the encryptors are Rust-based using ChaCha20 and RSA, target Windows and VMware ESXi (including VM shutdown and snapshot removal), perform intermittent encryption, and share many similarities with ALPHV/BlackCat; researchers also observed potential use of the Brutus botnet for initial access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
