Linux-Version der neuen Cicada-Ransomware zielt auf VMware ESXi-Server

Teilen:

A new ransomware-as-a-service (RaaS) operation is impersonating the legitimate Cicada 3301 organization and has already listed 19 victims on its extortion portal, as it quickly attacked companies worldwide.

The new cybercrime operation is named after and uses the same logo as the mysterious 2012-2014 online/real-world game named Cicada 3301 that involved elaborate cryptographic puzzles.

However, there’s no connection between the two, and the legitimate project has issued a statement to renounce any association with the threat actors and condemned the ransomware operation’s actions.

“We do not know the identity of the criminals behind these heinous crimes, and are not associated with these groups in any way,” reads the statement from the Cicada 3301 organization.

Launched in early June

The Cicada3301 RaaS first began promoting the operation and recruiting affiliates on June 29, 2024, in a forum post to the ransomware and cybercrime forum known as RAMP.

However, BleepingComputer is aware of Cicada attacks as early as June 6, indicating that the gang was operating independently before attempting to recruit affiliates.

Like other ransomware operations, Cicada3301 conducts double-extortion tactics where they breach corporate networks, steal data, and then encrypt devices. The encryption key and threats to leak stolen data are then used as leverage to scare victims into paying a ransom.

The threat actors operate a data leak site that is used as part of their double-extortion scheme.

An analysis of the new malware by Truesec revealed significant overlaps between Cicada3301 and ALPHV/BlackCat, indicating a possible rebrand or a fork created by former ALPHV’s core team members.

This is based on the fact that:

  • Both are written in Rust.
  • Both Use the ChaCha20 algorithm for encryption.
  • Both employ identical VM shutdown and snapshot-wiping commands.
  • Both use the same user interface command parameters, the same file naming convention, and the same ransom note decryption method.
  • Both use intermittent encryption on larger files.

For context, ALPHV performed an exit scam in early March 2024 involving fake claims about an FBI takedown operation after they stole a massive $22 million payment from Change Healthcare from one of their affiliates.

Truesec has also found indications that the Cicada3301 ransomware operation may partner with or utilize the Brutus botnet for initial access to corporate networks. That botnet was previously associated with global-scale VPN brute-forcing activities targeting Cisco, Fortinet, Palo Alto, and SonicWall appliances.

It’s worth noting that the Brutus activity was first spotted two weeks after ALPHV shut down operations, so the link between the two groups still stands in terms of timelines.

Yet another threat to VMware ESXi

Cicada3301 is a Rust-based ransomware operation with both Windows and Linux/VMware ESXi encryptors. As part of Truesec’s report, the researchers analyzed the VMWare ESXi Linux encryptor for the ransomware operation.

Like BlackCat and other ransomware families, such as RansomHub, a special key must be entered as a command line argument to launch the encryptor. This key is used to decrypt an encrypted JSON blob that contains the configuration that the encryptor will use when encrypting a device.

Truesec says that the encryptor checks for the validity of the key by using it to decrypt the ransom note and, if successful, continues with the rest of the encryption operation.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:27 pm, Juni 22, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
wenige Wolken
Luftfeuchtigkeit: 50 %
Druck: 1014 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 15 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 17 mph 48 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,045.12
-1.22%
Ethereum(ETH)
€1,972.48
-6.95%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.77
-4.85%
Solana(SOL)
€115.81
-6.21%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.135135
-4.88%
Shiba Inu(SHIB)
€0.000010
-4.77%
Pepe(PEPE)
€0.000008
-8.63%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen