Skip to content

cicada3301

Inactive

25 tracked victims · First seen Jun 4, 2024 · Last seen Sep 4, 2025

About

Aggregated threat-intel description

Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.

Sectors: Business Services, Technology, Manufacturing · Countries: US, GB, CA

Recent victims

View all →
VictimSectorCountryPostedStatus
CI EngineeringNot FoundUSSep 4, 2025
diasdeprimavera.com.brNot FoundBRJul 18, 2025
gatlogistica.com.brTransportation/LogisticsBRJul 18, 2025
B&M - Expertise - AuditBusiness ServicesFRJul 18, 2025
Burnham NationwideBusiness ServicesUSJul 18, 2025
SensicalNot FoundUSJul 18, 2025
СonasaNot FoundESJul 15, 2025
PACIFIC BIOLABSHealthcareUSJul 11, 2025
Mack Energy CorpEnergyUSJul 9, 2025
Asesoría BieitoNot FoundESApr 22, 2025
NatilaitNot FoundApr 22, 2025
Amazon TransportesTransportation/LogisticsBRApr 22, 2025
Správa služeb hlavního města PrahyPublic SectorCZApr 10, 2025
Eagle DistilleriesConsumer ServicesJOApr 5, 2025
I.A.T.S.E. Local 667/669Not FoundCAMar 25, 2025
MinebeaMitsumi IncManufacturingJPMar 22, 2025
Benjamin Consulting ServicesBusiness ServicesFeb 25, 2025
Executive AgendaBusiness ServicesUSFeb 25, 2025
Birdsall Muller LLCNot FoundUSFeb 25, 2025
Johnson's NurseryConsumer ServicesFeb 24, 2025
Digital Technology Co., Ltd.TechnologyJPFeb 23, 2025
Goldstein Law Group, S.C.Business ServicesUSFeb 23, 2025
Northern ManagementBusiness ServicesUSFeb 23, 2025
The Northwestern Illinois AssociationEducationUSFeb 23, 2025
Substitute Teacher ServiceEducationUSFeb 9, 2025

All ransomware groups · Dark web intelligence