cicada3301

Ransomware
Sourceransomware.live

About the group

Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group cicada3301 has 3 known ransomware victims. See the most affected sectors and countries and recent victims.

3known victims
3in Brazil
2sectors hit
Most attacked sectors
Transportation2
Retail & E-Commerce1
Most affected countries
🇧🇷 Brasil3
Recent victims
diasdeprimavera.com.brRetail & E-Commerce · BR · 2025-07-18
gatlogistica.com.brTransportation · BR · 2025-07-18
Amazon TransportesTransportation · BR · 2025-04-22

cicada3301 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →