Cicada3301

Inactive
Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.
75 Victims
Jun 3, 2024 First Discovered
Sep 3, 2025 Last Discovered
378 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Anti-DDoS
cicadabv7vicyvgz5khl7v2x5yygcgow7ryy6yppwmxii4eoobdaztqd.onion
Tools Used
DefenseEvasion
EDRSandBlast
DiscoveryEnum
ADRecon, PowerView, SoftPerfect NetScan
Exfiltration
RClone
LOLBAS
BCDEdit, PsExec, WMIC
Networking
GOST, Plink
Offsec
PowerSploit, Rubeus
Intelligence
Victims (75)

Detailed victim list temporarily unavailable

This group has 75 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.