logo

Linux version of new Cicada ransomware targets VMware ESXi servers

ID: 8f3bf995-540c-57ac-9d61-9c46102c918f

STIX ID: report--8f3bf995-540c-57ac-9d61-9c46102c918f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new RaaS operation calling itself Cicada3301 is actively conducting double-extortion ransomware attacks worldwide against Windows and VMware ESXi systems; analysis shows Rust-based encryptors using ChaCha20, intermittent encryption, VM shutdown and snapshot-wiping commands, and strong overlaps with ALPHV/BlackCat tactics and tooling. The group has advertised on cybercrime forums, may leverage the Brutus botnet for initial access, and is operating an extortion portal listing multiple victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.