Cicada3301 is a ransomware-as-a-service operation first observed in June 2024 that deploys a Rust-based ransomware family against Windows and Linux, including VMware ESXi environments. The operation uses double extortion, combining file encryption with data theft and leak-site pressure, and has been tracked as an emerging ransomware brand in 2024.
The malware has been analyzed most closely in its Linux/ESXi form, where it appears as a Rust-compiled ELF binary. Available reporting indicates the Windows and ESXi builds are likely the same codebase compiled for different targets. The ransomware uses ChaCha20 for file encryption, generates per-file symmetric material with operating-system randomness, and protects that material with an embedded public key. It encrypts smaller files fully and larger files partially for speed, appends its encrypted-file metadata to affected files, and drops ransom notes in directories containing encrypted content. On ESXi, it can terminate virtual machines and remove snapshots unless instructed not to, reflecting optimization for virtualized enterprise environments.
Cicada3301 exposes command-line options including delayed execution, progress display, snapshot-handling control, and a required key parameter used to validate and decrypt an embedded ransom-note blob. Technical analysis has identified multiple similarities with ALPHV/BlackCat, including the use of Rust, ChaCha20-based encryption, closely similar ESXi virtual-machine shutdown and snapshot-deletion logic, and comparable ransom-note conventions. These overlaps have led to assessments that Cicada3301 may be a rebrand, derivative, or code-descended successor to ALPHV, although a direct relationship remains unverified.
Observed intrusion activity associated with Cicada3301 indicates initial access may be obtained through valid accounts used over remote access software, with reporting linking some activity to credentials believed stolen or brute-forced and to infrastructure associated with the Brutus botnet. Additional reporting notes attempts by Cicada3301 operators to exploit ScreenConnect vulnerabilities. The group has also been discussed in connection with infrastructure overlap involving ShadowSyndicate, a cluster associated with multiple ransomware ecosystems, though such overlap does not by itself establish operational control.
Cicada3301 targets enterprise environments and has been observed in ransomware victim reporting across multiple sectors and regions. Its support for Windows and ESXi, combined with behavior tailored to virtual infrastructure, makes it particularly relevant to organizations operating mixed server estates and virtualization platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found that at least one IP address ... was overlapping with the ShadowSyndicate attack infrastructure and an exfiltration server used by affiliates of a recent RaaS program known as Cicada3301.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The files will then be encrypted with a symmetric key generated by OsRng using ChaCha20. | If it is greater than 0x6400000, then it will encrypt the file in parts, and if it is smaller, the whole file will be encrypted.
Both use almost identical commands to shutdown VM and remove snapshots... esxcli vm process kill –type=force –world-id=
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cicada3301 is a ransomware group responsible for at least two incidents in Japan in the first half of 2025.
Ransomware operation referenced as active in Q2 2025 (no additional detail provided).
Rust-based ransomware-as-a-service first observed in June 2024; discussed as potentially a BlackCat/ALPHV rebrand and linked to ScreenConnect exploitation and overlapping infrastructure with ShadowSyndicate.
A ransomware family appearing as a new top variant by market share in Q3 2024.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.