By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program
Tech News

Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program

By Viral Trending Content 4 Min Read
Share
SHARE

Oct 17, 2024Ravie LakshmananRansomware / Network Security

Cicada3301 Ransomware

Cybersecurity researchers have gleaned additional insights into a nascent ransomware-as-a-service (RaaS) called Cicada3301 after successfully gaining access to the group’s affiliate panel on the dark web.

Singapore-headquartered Group-IB said it contacted the threat actor behind the Cicada3301 persona on the RAMP cybercrime forum via the Tox messaging service after the latter put out an advertisement, calling for new partners into its affiliate program.

“Within the dashboard of the Affiliates’ panel of Cicada3301 ransomware group contained sections such as Dashboard, News, Companies, Chat Companies, Chat Support, Account, an FAQ section, and Log Out,” researchers Nikolay Kichatov and Sharmine Low said in a new analysis published today.

Cybersecurity

Cicada3301 first came to light in June 2024, with the cybersecurity community uncovering strong source code similarities with the now-defunct BlackCat ransomware group. The RaaS scheme is estimated to have compromised no less than 30 organizations across critical sectors, most of which are located in the U.S. and the U.K.

The Rust-based ransomware is cross-platform, allowing affiliates to target devices running Windows, Linux distributions Ubuntu, Debian, CentOS, Rocky Linux, Scientific Linux, SUSE, Fedora, ESXi, NAS, PowerPC, PowerPC64, and PowerPC64LE.

Like other ransomware strains, attacks involving Cicada3301 have the ability to either fully or partially encrypt files, but not before shutting down virtual machines, inhibiting system recovery, terminating processes and services, and deleting shadow copies. It’s also capable of encrypting network shares for maximum impact.

“Cicada3301 runs an affiliate program recruiting penetration testers (pentesters) and access brokers, offering a 20% commission, and providing a web-based panel with extensive features for affiliates,” the researchers noted.

Cicada3301 Ransomware

A summary of the different sections is as follows –

  • Dashboard – An overview of the successful or failed logins by the affiliate, and the number of companies attacked
  • News – Information about product updates and news of the Cicada3301 ransomware program
  • Companies – Provides options to add victims (i.e., company name, ransom amount demanded, discount expiration date etc.) and create Cicada3301 ransomware builds
  • Chat Companies – An interface to communicate and negotiate with victims
  • Chat Support – An interface for the affiliates to communicate with representatives of the Cicada3301 ransomware group to resolve issues
  • Account – A section devoted to affiliate account management and resetting their password
  • FAQ – Provides details about rules and guides on creating victims in the “Companies” section, configuring the builder, and steps to execute the ransomware on different operating systems
Cybersecurity

“The Cicada3301 ransomware group has rapidly established itself as a significant threat in the ransomware landscape, due to its sophisticated operations and advanced tooling,” the researchers said.

“By leveraging ChaCha20 + RSA encryption and offering a customizable affiliate panel, Cicada3301 enables its affiliates to execute highly targeted attacks. Their approach of exfiltrating data before encryption adds an additional layer of pressure on victims, while the ability to halt virtual machines increases the impact of their attacks.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

lynx, beavers, and aurochs benefit landscapes

Dell Pro Max 18 Plus: Desktop Power in a Portable Laptop

CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat

ATG, ÉireComposites to build satellite parts for ESA gravitational waves mission

With the Rise of AI, Cisco Sounds an Urgent Alarm About the Risks of Aging Tech

TAGGED: Cyber Security, Cybercrime, Cybersecurity, dark web, encryption, Internet, network security, Ransomware, ransomware-as-a-service, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Bitcoin Exchange Exodus: Investors Withdrew $24 Billion In BTC Over Last 8 Months
Next Article Xcel Energy faces new requirements for preemptive power shutoffs after storm of complaints
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The Johor-Singapore SEZ will be more than an ‘industrial park with a nicer brochure,’ says the chair of the state’s investment committee
Business
Bitcoin Loses Ground As Ethereum Takes The Lead In This Major Metric
Crypto
Nigerian separatist leader sentenced to life for terrorism
World News
India taps Polygon and Anq for its rupee-backed stablecoin, set to launch in early 2026
Crypto
lynx, beavers, and aurochs benefit landscapes
Tech News
Cappuccino for €2.50? Affordable café chain LAP divides Berlin over coffee prices
Business
Where in the EU sees the most long-term unemployment?
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The Johor-Singapore SEZ will be more than an ‘industrial park with a nicer brochure,’ says the chair of the state’s investment committee

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The Johor-Singapore SEZ will be more than an ‘industrial park with a nicer brochure,’ says the chair of the state’s investment committee
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?