Linux version of new Cicada ransomware targets VMware ESXi servers
ID: 8f3bf995-540c-57ac-9d61-9c46102c918f
STIX ID: report--8f3bf995-540c-57ac-9d61-9c46102c918f
Feed Name: Bleeping Computer
A new RaaS operation calling itself Cicada3301 is actively conducting double-extortion ransomware attacks worldwide against Windows and VMware ESXi systems; analysis shows Rust-based encryptors using ChaCha20, intermittent encryption, VM shutdown and snapshot-wiping commands, and strong overlaps with ALPHV/BlackCat tactics and tooling. The group has advertised on cybercrime forums, may leverage the Brutus botnet for initial access, and is operating an extortion portal listing multiple victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
