Cicada3301 Ransomware Group

Also known as: Cicada3301 Ransomware Group

A suspected ransomware-as-a-service (“RaaS”) group first observed in June 2024, which extorts victims via traditional ransomware encryption and by threatening to leak allegedly exfiltrated data onto the web.[Truesec AB August 30 2024]

Introduction

A suspected ransomware-as-a-service (“RaaS”) group first observed in June 2024, which extorts victims via traditional ransomware encryption and by threatening to leak allegedly exfiltrated data onto the web.[Truesec AB August 30 2024]

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

Information pending cataloguing.

Attribution and Evidence

Information pending cataloguing.

References

[1] [Truesec AB August 30 2024