◇ SIGN IN
← all actors
ransomware

Cicada3301

activemedium confidence
Ransomware
Cicada 3301
Attribution
RaaS (suspected ALPHV/BlackCat successor or builder purchaser)
Origin
Unknown
First seen
2024
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Jordan, Tunisia, UAE
Sectors
Beverage/manufacturing, dairy/food, industrial

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Jordan, Tunisia, UAE (Beverage/manufacturing, dairy/food, industrial sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Cicada3301 is a Rust-based ransomware-as-a-service operation that began recruiting affiliates in mid-2024, showing strong technical similarities to the defunct ALPHV/BlackCat and suspected to be either a rebrand or a purchaser of its source code.

History

Cicada3301 began advertising on darknet forums and recruiting affiliates around late June 2024, listing its first victims soon after (initially mostly in the US and UK). The ransomware is written in Rust and targets both Windows and Linux/ESXi environments, and analysts (SecurityWeek, Truesec, IBM and others) documented multiple similarities to ALPHV/BlackCat's encryptor and operational style following ALPHV's early-2024 exit scam.

Whether Cicada3301 is a direct ALPHV/BlackCat rebrand or an unrelated crew that acquired the leaked/sold source code remains unresolved; the group markets its RaaS aggressively, reportedly offering affiliates around a 20% cut and providing a web panel for victim management, chats and negotiations. Security researchers subsequently reported infiltrating the affiliate program, yielding additional insight into its operations.

Cicada3301 remained active through 2025 with a global victim spread. Its MENA-relevant claims include Jordan, Tunisia and the UAE. As with all RaaS leak-site postings, individual victim claims should be treated as unverified unless independently confirmed by a reputable source or the affected organization.

Notable campaigns

2024
Cicada3301 RaaS launch
Began affiliate recruitment and victim listings in mid-2024 with a Rust-based cross-platform encryptor.
2025
Affiliate program infiltration
Security researchers reported infiltrating Cicada3301's affiliate panel, exposing operational details.

Claimed victims · 75 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
CI EngineeringUSProfessional Services
diasdeprimavera.com.brBRRetail & E-Commerce
gatlogistica.com.brBRTransportation
B&M - Expertise - AuditFRProfessional Services
Burnham NationwideUSProfessional Services
SensicalUSTechnology
СonasaESManufacturing
PACIFIC BIOLABSUSHealthcare
Mack Energy CorpUSEnergy & Utilities
Asesoría BieitoESProfessional Services
NatilaitTunisiaAgriculture and Food Production
Amazon TransportesBRTransportation