Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers uncover Cicada3301 ransomware operations and its affiliate program
Global Security

Researchers uncover Cicada3301 ransomware operations and its affiliate program

AdminBy AdminOctober 17, 2024No Comments3 Mins Read
Cicada3301 Ransomware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 17, 2024Ravi LakshmananRansomware / Network Security

Cicada3301 ransomware

Cybersecurity researchers have gathered more information about a nascent ransomware-as-a-service (RaaS) called Cicada3301 after successfully gaining access to the group’s affiliate panel on the dark web.

Singapore-headquartered Group-IB said it contacted the threat actor behind the persona Cicada3301 on the RAMP cybercrime forum via the Tox messaging service after the latter posted an ad calling for new partners in its affiliate program.

“The Cicada3301 ransomware group’s affiliate panel dashboard had sections like Control Panel, News, Campaigns, Chat Campaigns, Chat Support, Account, FAQ section questions and “Exit” – researchers Mikalai Kichatov and Sharmin Lowe. said in a new analysis published today.

Cyber ​​security

Cicada3301 was born for the first time in June 2024, the cybersecurity community discovered strong similarities in the source code to the now-defunct BlackCat ransomware group. The RaaS scheme is estimated to have compromised at least 30 organizations in critical sectors, most of them in the US and UK

Based on Rust, the ransomware is cross-platform, allowing branches to target devices running Windows, Linux distributions Ubuntu, Debian, CentOS, Rocky Linux, Scientific Linux, SUSE, Fedora, ESXi, NAS, PowerPC, PowerPC64 and PowerPC64LE .

Like other types of ransomware, attacks involving Cicada3301 have the ability to fully or partially encrypt files, but not before shutting down virtual machines, prohibiting system recovery, stopping processes and services, and deleting shadow copies. It is also capable of encrypting shared network files for maximum impact.

“Cicada3301 is launching an affiliate program recruiting penetration testers (pentesters) and access brokers, offering 20% ​​commissions and providing a web dashboard with extensive affiliate opportunities,” the researchers noted.

Cicada3301 ransomware

A summary of the various sections is as follows –

  • Dashboard – Overview of successful and unsuccessful logins by partners, as well as the number of attacked companies
  • News – Information about Cicada3301 ransomware product updates and news
  • Companies – Provides options for adding victims (such as company name, ransom amount required, discount expiration date, etc.) and creating Cicada3301 ransomware builds
  • Chat companies – Interface for communication and negotiation with victims
  • Chat support – Interface for affiliates to communicate with representatives of the Cicada3301 ransomware group to resolve issues
  • Account – Section dedicated to managing partner accounts and resetting their passwords
  • FAQ – Provides detailed information on the rules and instructions for creating victims in the Campaigns section, configuring the builder, and steps to run ransomware on various operating systems
Cyber ​​security

“The Cicada3301 ransomware group has quickly established itself as a significant threat in the ransomware landscape due to its sophisticated operations and sophisticated tools,” the researchers said.

“Using ChaCha20 + RSA encryption and offering a customizable partner panel, Cicada3301 allows its partners to perform highly targeted attacks. Their approach of stealing data before encryption creates an additional layer of pressure on victims, while the ability to shut down virtual machines increases the impact of their attacks.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.