Home Hardware Tutorial Hardware News Windows and Linux vulnerable to oddly familiar Cicada3301 ransomware

Windows and Linux vulnerable to oddly familiar Cicada3301 ransomware

Sep 04, 2024 am 06:43 AM
laptop test Notebook review reviews tests reports netbook

Windows and Linux vulnerable to oddly familiar Cicada3301 ransomware

A relatively new piece of ransomware, called Cicada3301, has been analyzed in detail by cybersecurity researchers, and the findings reveal surprising callbacks to infamous attacks from the recent past. Cicada3301 is able to target Linux-based and Windows systems.

This new malware bears a resemblance to BlackCat, the ransomware used in the 2021 attack on the Colonial Pipeline. The unique factor is that Cicada3301 uses a two-pronged approach to make victims pay up; not only are files encrypted, they're also packaged and leaked if payment isn't made.

Cicada3301 was first spotted in June of 2024, when the first leak of a victim's data showed up on the dedicated site set up by its creators. They later took to a Russian dark web forum called RAMP with the aim of soliciting affiliates. They offered Cicada3301 as a service, offering to attack selected targets for a price. This model, called ransomware-as-a-service, has gained popularity among bad actors in recent years.

Victims will find their systems largely immune to traditional efforts used to stem ransomware attacks thanks to a clever mix of tactics built into Cicada3301. They will instead be greeted by a lone text file offering instructions to save their files from being leaked. According to the text file, the group behind this attack includes an offer to tighten up victims' security to prevent similar attacks in the future, as well as ongoing support, should a victim choose to pay up.

The website and resources utilized by the group behind the 2021 attack were eventually seized by US authorities. It is believed that the group has ceased activities, but the similarities that Cicada3301 bears to BlackCat and its rebrand, ALHPV, are numerous.

Cicada3301 is written in the Rust programming language, making it versatile, efficient, and extensible, but this could be written off as merely following the trend established by BlackCat; up until that attack, ransomware written in Rust was extremely uncommon, and was more often than not a mere proof-of-concept shown off by white hat hackers across the web.

Beyond using the same programming language and general attack structure, Cicada3301 uses similar decryption methods, and many commands written into the new malware are exactly the same as function calls found in BlackCat. In both attacks, legitimate user credentials are obtained through any available means, often social engineering, and used to gain access to the target system.

From there, both attacks use almost identical calls to do things like phone home, encrypt and decrypt files, display messages, and more. Cicada3301 does, however, come with some new tricks. Chief among them is the ability to stop outside machines, including virtual machines, from accessing encrypted files and systems.

As of September of 2024, all resources linked to Cicada3301 are seemingly still live, and there have been no reports of any bad actors connected to it stepping down or being apprehended. It is possible that the new ransomware is the creation of one or more team members from the BlackCat attacks, or a rival group that copied much of the code of BlackCat before it went dark.

The above is the detailed content of Windows and Linux vulnerable to oddly familiar Cicada3301 ransomware. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Nordhold: Fusion System, Explained
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1676
14
PHP Tutorial
1278
29
C# Tutorial
1257
24
Huawei Watch GT 5 smartwatch gets update with new features Huawei Watch GT 5 smartwatch gets update with new features Oct 03, 2024 am 06:25 AM

Huawei is rolling out software version 5.0.0.100(C00M01) for the Watch GT 5 and the Watch GT 5 Prosmartwatchesglobally. These two smartwatches recently launched in Europe, with the standard model arriving as the company’s cheapest model. This Harmony

Tekken\'s Colonel Sanders dream fried by KFC Tekken\'s Colonel Sanders dream fried by KFC Oct 02, 2024 am 06:07 AM

Katsuhiro Harada, the Tekken series director, once seriously tried to bring Colonel Sanders into the iconic fighting game. In an interview with TheGamer, Harada revealed that he pitched the idea to KFC Japan, hoping to add the fast-food legend as a g

Cybertruck FSD reviews praise quick lane switching and full-screen visualizations Cybertruck FSD reviews praise quick lane switching and full-screen visualizations Oct 01, 2024 am 06:16 AM

Tesla is rolling out the latest Full Self-Driving (Supervised) version 12.5.5 and with it comes the promised Cybertruck FSD option at long last, ten months after the pickup went on sale with the feature included in the Foundation Series trim price. F

Garmin releases Adventure Racing activity improvements for multiple smartwatches via new update Garmin releases Adventure Racing activity improvements for multiple smartwatches via new update Oct 01, 2024 am 06:40 AM

Garmin is ending the month with a new set of stable updates for its latest high-end smartwatches. To recap, the company released System Software 11.64 to combat high battery drain across the Enduro 3, Fenix E and Fenix 8 (curr. $1,099.99 on Amazon).

New Xiaomi Mijia Graphene Oil Heater with HyperOS arrives New Xiaomi Mijia Graphene Oil Heater with HyperOS arrives Oct 02, 2024 pm 09:02 PM

Xiaomi will shortly launch the Mijia Graphene Oil Heater in China. The company recently ran a successful crowdfunding campaign for the smart home product, hosted on its Youpin platform. According to the page, the device has already started to ship to

First look: Leaked unboxing video of upcoming Anker Zolo 4-port 140W wall charger with display First look: Leaked unboxing video of upcoming Anker Zolo 4-port 140W wall charger with display Oct 01, 2024 am 06:32 AM

Earlier in September 2024, Anker's Zolo 140W charger was leaked, and it was a big deal since it was the first-ever wall charger with a display from the company. Now, a new unboxing video from Xiao Li TV on YouTube gives us a first-hand look at the hi

Samsung Galaxy Z Fold Special Edition revealed to land in late October as conflicting name emerges Samsung Galaxy Z Fold Special Edition revealed to land in late October as conflicting name emerges Oct 01, 2024 am 06:21 AM

The launch of Samsung's long-awaited 'Special Edition' foldable has taken another twist. In recent weeks, rumours about the so-called Galaxy Z Fold Special Edition went rather quiet. Instead, the focus has shifted to the Galaxy S25 series, including

Manjaro 24.1 \'Xahea\' launches with KDE Plasma 6.1.5, VirtualBox 7.1, and more Manjaro 24.1 \'Xahea\' launches with KDE Plasma 6.1.5, VirtualBox 7.1, and more Oct 02, 2024 am 06:06 AM

With a history of over one decade, Manjaro is regarded as one of the most user-friendly Linux distros suitable for both beginners and power users, being easy to install and use. Mostly developed in Austria, Germany, and France, this Arch-based distro

See all articles