[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Navin Thomas](https://unit42.paloaltonetworks.com/author/navin-thomas/)
  * [Jerome Tujague](https://unit42.paloaltonetworks.com/author/jerome-tujague/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 10, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [ALPHV](https://unit42.paloaltonetworks.com/tag/alphv/)
  * [Ambitious Scorpius](https://unit42.paloaltonetworks.com/tag/ambitious-scorpius/)
  * [Bashful Scorpius](https://unit42.paloaltonetworks.com/tag/bashful-scorpius/)
  * [BlackCat ransomware](https://unit42.paloaltonetworks.com/tag/blackcat-ransomware/)
  * [Cicada3301](https://unit42.paloaltonetworks.com/tag/cicada3301/)
  * [CVE-2024-1708](https://unit42.paloaltonetworks.com/tag/cve-2024-1708/)
  * [CVE-2024-1709](https://unit42.paloaltonetworks.com/tag/cve-2024-1709/)
  * [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/)
  * [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/)
  * [Nokoyawa](https://unit42.paloaltonetworks.com/tag/nokoyawa/)
  * [RaaS](https://unit42.paloaltonetworks.com/tag/raas/)
  * [Repellent Scorpius](https://unit42.paloaltonetworks.com/tag/repellent-scorpius/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/repellent-scorpius-cicada3301-ransomware/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/repellent-scorpius-cicada3301-ransomware/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Assessment:%20Repellent%20Scorpius,%20Distributors%20of%20Cicada3301%20Ransomware&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F&title=Threat%20Assessment:%20Repellent%20Scorpius,%20Distributors%20of%20Cicada3301%20Ransomware "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F&text=Threat%20Assessment:%20Repellent%20Scorpius,%20Distributors%20of%20Cicada3301%20Ransomware "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Assessment:%20Repellent%20Scorpius,%20Distributors%20of%20Cicada3301%20Ransomware%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frepellent-scorpius-cicada3301-ransomware%2F "Share in Mastodon")

## Executive Summary

Repellent Scorpius is a new ransomware-as-a-service (RaaS) group that distributes Cicada3301 ransomware. The ransomware group appears to have first emerged in May 2024, with a multi-extortion operation.

This report based on Unit 42 Incident Response engagements provides a technical analysis of the ransomware employed by the Repellent Scorpius group. It also covers other tactics, techniques and procedures (TTPs) observed during this attack.

In addition, we discuss Repellent Scorpius' connection to a historical incident involving data exfiltration, predating the group's operation under the Cicada3301 brand, as well as the ransomware group's plans going forward. Finally, we provide a walkthrough of an updated encryptor obtained through external sources, highlighting the differences from its previous variant. Unit 42 anticipates a rise in Cicada3301 ransomware activity, leading to an increase in the number of victims.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)
* [Advanced WildFire](https://docs.paloaltonetworks.com/advanced-wildfire)
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/how-url-filtering-works) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security/administration/about-dns-security)
* Prisma Cloud through the [Cloud Security Agent (CSA)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Pairing-Prisma-Cloud-Compute-with-Cortex-XDR)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Cybercrime**](https://unit42.paloaltonetworks.com/category/cybercrime/), **[RaaS](https://unit42.paloaltonetworks.com/tag/raas/)** |
|----------------------------|---------------------------------------------------------------------------------------------------------------------------------------|

## Repellent Scorpius Threat Overview

Repellent Scorpius (distributors of Cicada3301 ransomware) is a new threat group that has recently emerged in the wild. Despite its recent inception, it is quickly picking up pace by setting up an affiliate program and recruiting partners. This has increased its number of victims according to the leak site.

There is an intriguing background associated with the name under which the ransomware group operates. According to [Wikipedia](https://en.wikipedia.org/wiki/Cicada_3301), the name 3301 refers to three sets of highly complex and mysterious puzzles that first appeared on 4chan between 2012-2014, all signed with the pseudonym 3301. The third set of these puzzles remains unsolved to this day.

Based on the timeline from a Unit 42 Incident Response engagement, we estimate that the ransomware group began their operations in May 2024. Owing to the absence of other reports, we believe that this may be the beginning of their operations.

While the incidents may have begun around that time, we started to observe leak site activity in June. Despite a lack of activity on the leak site for around a month since June 19, the ransomware group has resumed operations.

Of note, we have observed signs that the group has data obtained in older compromise incidents. It is unclear whether this means that the threat actor previously operated using differently branded ransomware, or whether they have purchased or inherited data from other ransomware groups.
![Screenshot of Cicada3301 leak site showing multiple posts with publication dates. Each post has redacted information image and text, with visible options to 'Open Post', 'User Info', and a 'Connect' button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-766319-136638-1.png) Figure 1. Cicada3301 leak site as of July 2024.

Repellent Scorpius employs a double extortion scheme of encrypting systems. This entails stealing data and threatening to publish it if the victim doesn't pay the ransom.

Unit 42 has evidence to suggest that the Repellent Scorpius operators have developed a RaaS affiliate program. It operates a control panel for affiliates and ransom payment pages for victims, and actively recruits initial access brokers (IAB) and network intruders on Russian-language cybercrime forums.

Given the limited number of victims, it might be too early to suggest whether this ransomware group targets a particular sector or region. Having said that, one of the points in the FAQ section on the affiliate panel website says, "It is strictly prohibited to target the CIS countries." (Translated from Russian.)

KrakenLabs [posted a screenshot on X](https://x.com/KrakenLabs_Team/status/1812805505594847449) (formerly Twitter), displaying a Russian translated post by the Repellent Scorpius ransomware group on an underground forum to recruit partners for their affiliate program.

## Incident Attack Lifecycle

We have mapped the attack stages captured from our incident response engagement to the [MITRE ATT\&CK® framework](https://attack.mitre.org/) tactics, which we summarize below.

### Initial Access

Multiple Remote Desktop Protocol (RDP) logon events were captured on a given host. Based on investigation findings and the group's modus operandi, we assess that attackers achieved initial access through stolen credentials, possibly purchased from an IAB.

The public IP address predominantly associated was 103.42.240\[.\]37, as an RDP server with the hostname: WIN-RMM48SHAUPR. This IP address is associated with a Pakistan-based hosting provider 0DAYHOST (SMC-PRIVATE) LIMITED, while the autonomous system name indicates that Serverius Holding B.V. controls the IP address allocation.

### Execution

Unit 42 investigators observed attackers employing a batch script named 1.bat to execute the ransomware payload against multiple hosts within the client network. Details regarding the ransomware payload, along with its arguments, are below.
![Text file displaying multiple lines of code, with some information redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-770620-136638-2.png) Figure 2. Batch script with multiple ransomware command executions.

### Lateral Movement

[PsExec](https://learn.microsoft.com/en-us/sysinternals/downloads/psexec) is a legitimate tool that attackers leveraged to execute the ransomware payload against different hosts within the network. The tool is embedded within the ransomware payload and later extracted, which we describe in further detail below. It was executed through the following PowerShell command:  
powershell -Command C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\locker.exe" --no\_impl --key \<redacted\> -p \\\\\<hostname\>\\C$

|---|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | powershell -Command C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\locker.exe" --no\_impl --key \<redacted\> -p \\\\\<hostname\>\\C$ |

### Collection

Unit 42 investigators found the creation of the following file C:\\ProgramData\\found\_shares.txt. There have been previous occurrences of PowerView, a [PowerSploit](https://powersploit.readthedocs.io/en/latest/Recon/) PowerShell module, storing file share enumeration results in the same file path and multiple ransomware intrusions have leveraged this technique.

### Exfiltration

Unit 42 investigators identified [Rclone](https://rclone.org/) (a legitimate open-source utility) as the tool used for exfiltration. Attackers installed the tool in the *ProgramData* file path (C:\\ProgramData\\rclone.exe), along with the configuration file (C:\\ProgramData\\rclone.conf).

We observed 91.238.181\[.\]238 was the public IP address attackers used for exfiltration activity. This IP address comes from a hosting provider called VDS\&VPN services.

The IP address in question has previously been flagged for Cobalt Strike activity (watermark: 674054486) and was potentially [linked to other ransomware groups](https://twitter.com/TLP_R3D/status/1718188502406385955) such as Bashful Scorpius (aka Nokoyawa) and Ambitious Scorpius (aka ALPHV/BlackCat) in 2023. This IP address was also observed trying to exploit ScreenConnect vulnerabilities, ([CVE-2024-1708 and CVE-2024-1709) in February 2024](https://unit42.paloaltonetworks.com/connectwise-threat-brief-cve-2024-1708-cve-2024-1709/).

### Impact (Encryptor)

The ransomware is a 64-bit binary written in the programing language [Rust](https://www.rust-lang.org/), which accepts the following command-line arguments:  
USAGE: locker.exe \[FLAGS\] \[OPTIONS\] Additional Information: --key Sets the keys for activation (Required parameter) -p, --path Sets the path to the file or directory to be encrypted -s, --sleep Sleep is indicated in seconds --no\_local Skip encrypting data stored locally on this device --no\_net Skip encryption of network data --no\_impl Don't use impersonation

|-------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | USAGE: locker.exe \[FLAGS\] \[OPTIONS\] Additional Information: --key Sets the keys for activation (Required parameter) -p, --path Sets the path to the file or directory to be encrypted -s, --sleep Sleep is indicated in seconds --no\_local Skip encrypting data stored locally on this device --no\_net Skip encryption of network data --no\_impl Don't use impersonation |

Figure 2 shows the threat actors used a batch script to execute the ransomware multiple times against a list of hard-coded directory paths in the victim network. The encryptor requires a key parameter to begin execution, which has been redacted from the image.

The binary performs a key validation routine, in which it attempts to decrypt an embedded ransom note using the [ChaCha20 stream cipher \[PDF\]](https://cr.yp.to/chacha/chacha-20080128.pdf).

The ransomware note is Base64-decoded. It is then decrypted using the first 32 bytes of the submitted key as the ChaCha20 secret key and the last 12 bytes of the submitted key as the nonce. Then it is Base64-decoded a final time.

The encryptor will validate the decryption process by checking whether the string \*\*\*is\_ok\*\*\* exists in the decrypted data. If the validation is successful, execution proceeds.

The encryptor contains a legitimate copy of PsExec embedded within itself, which it will extract and save to the location C:\\Users\\Public\\psexec0.exe. The malware will then create a copy of itself in the C:\\Users\\Public\\ directory.

Once copied, it will use the PsExec binary to execute itself several more times, using hard-coded credentials stolen from the victim network during the preceding incursion. This may be an attempt to get the encryptor to run with higher privileges.  
C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\\<encryptor\>" --no\_impl --key \<key\> C:\\Users\\Public\\psexec0.exe -accepteula -u \<username\> -p \<password\> -s -d "C:\\Users\\Public\\\<encryptor\>" --no\_impl --key \<key\>

|-------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\\<encryptor\>" --no\_impl --key \<key\> C:\\Users\\Public\\psexec0.exe -accepteula -u \<username\> -p \<password\> -s -d "C:\\Users\\Public\\\<encryptor\>" --no\_impl --key \<key\> |

Next, the encryptor will run a series of commands to terminate services and processes, delete shadow copies and disable recovery features among other tasks. A list of the executed commands is below, and a full list of targeted processes and services is in the appendix.

|---------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------|
| **Command**                                                                                                                           | **Purpose**                                                                                           |
| cmd /C fsutil behavior set SymlinkEvaluation R2L:1                                                                                    | Enables remote to local symbolic links                                                                |
| cmd /C fsutil behavior set SymlinkEvaluation R2R:1                                                                                    | Enables remote to remote symbolic links                                                               |
| cmd /C iisreset.exe /stop                                                                                                             | Stops Internet Information Services (IIS)                                                             |
| cmd /C vssadmin.exe Delete Shadows /all /quiet                                                                                        | Deletes volume shadow copies using VSSAdmin.exe                                                       |
| cmd /C wmic.exe Shadowcopy Delete                                                                                                     | Deletes volume shadow copies using the Windows Management Instrumentation Command-Line (WMIC) utility |
| cmd /C bcdedit /set {default}                                                                                                         | Possibly a misused command, as it requires additional parameters to execute properly                  |
| cmd /C bcdedit /set {default} recoveryenabled No                                                                                      | Disables the automatic recover feature for the default boot entry                                     |
| cmd /C "for /F 'tokens=\*' %1 in ('wevtutil.exe el') DO wevtutil.exe cl %1"                                                           | Clears Windows Event Logs                                                                             |
| cmd /C reg add HKEY\_LOCAL\_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters /v MaxMpxCt /d 65535 /t REG\_DWORD /f | Sets the number of concurrent network requests to the maximum allowed                                 |
| cmd /C sc stop \<service\>                                                                                                            | Stops the specified service                                                                           |
| cmd /C taskkill /IM \<process\>\* /F                                                                                                  | Forcefully terminates the specified process                                                           |

Once the sample completes the above processes, it begins the encryption routine. By default, the ransomware will check for the existence of drives from A:\\ to Z:\\. The sample encrypts all files within detected drives, excluding files with specific extensions or files located in directories matching keywords. This information is listed in the appendix.

The encryptor renames files with a new extension before starting the encryption process. In the sample analyzed by Unit 42 the extension was kcr5umw.

The encryption process is composed of two sequences. First, the encryptor will read the contents of the target file, encrypt the contents using ChaCha20 with a randomly generated key secret and nonce bytes, and write the result back to the file. Second, the ChaCha20 key and nonce are encrypted using a hard-coded RSA public key, and the result is appended to the file. Finally, the extension is appended to the end of the encrypted data.

Once encryption of all files is complete, the sample will write the ransom note, named in the format RECOVER-\<encrypted\_file\_extension\>-DATA.txt. The contents of the note are as follows.  
\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \*\*\* Welcome to Cicada3301 \*\*\* \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \*\* What Happened? \*\* ---------------------------------------------- Your computers and servers are encrypted, your backups are deleted. We use strong encryption algorithms, so you won't be able to decrypt your data. You can recover everything by purchasing a special data recovery program from us. This program will restore your entire network. \*\* Data Leak \*\* ---------------------------------------------- We have downloaded more than %SIZE% GB of your company data. Contact us, or we will be forced to publish all your data on the Internet and send it to all regulatory authorities in your country, as well as to your customers, partners, and competitors. We are ready to: - Provide you with proof that the data has been stolen; - Delete all stolen data; - Help you rebuild your infrastructure and prevent similar attacks in the future; \*\* What Guarantees? \*\* ---------------------------------------------- Our reputation is of paramount importance to us. Failure to fulfill our obligations means not working with you, which is against our interests. Rest assured, our decryption tools have been thoroughly tested and are guaranteed to unlock your data. Should any problems arise, we are here to support you. As a goodwill gesture, we are willing to decrypt one file for free. \*\* How to Contact us? \*\* ---------------------------------------------- Using TOR Browser: 1) You can download and install the TOR browser from this site: https://torproject.org/ 2) Open our website: \<redacted\> WARNING: DO NOT MODIFY or attempt to restore any files on your own. This can lead to their permanent loss.

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 | \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \*\*\* Welcome to Cicada3301 \*\*\* \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \*\* What Happened? \*\* ---------------------------------------------- Your computers and servers are encrypted, your backups are deleted. We use strong encryption algorithms, so you won't be able to decrypt your data. You can recover everything by purchasing a special data recovery program from us. This program will restore your entire network. \*\* Data Leak \*\* ---------------------------------------------- We have downloaded more than %SIZE% GB of your company data. Contact us, or we will be forced to publish all your data on the Internet and send it to all regulatory authorities in your country, as well as to your customers, partners, and competitors. We are ready to: - Provide you with proof that the data has been stolen; - Delete all stolen data; - Help you rebuild your infrastructure and prevent similar attacks in the future; \*\* What Guarantees? \*\* ---------------------------------------------- Our reputation is of paramount importance to us. Failure to fulfill our obligations means not working with you, which is against our interests. Rest assured, our decryption tools have been thoroughly tested and are guaranteed to unlock your data. Should any problems arise, we are here to support you. As a goodwill gesture, we are willing to decrypt one file for free. \*\* How to Contact us? \*\* ---------------------------------------------- Using TOR Browser: 1) You can download and install the TOR browser from this site: https://torproject.org/ 2) Open our website: \<redacted\> WARNING: DO NOT MODIFY or attempt to restore any files on your own. This can lead to their permanent loss. |

## Links to Historical Incident

Unit 42 is aware of at least one case where Repellent Scorpius had access to a victim's data, which attackers likely took in an incident several years prior. A forensic review of the victim's environment identified no recent signs of compromise. A quick walkthrough of some of the TTPs observed during that incident were as follows:

|---------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **MITRE Tactic**    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Execution           | \* WinRAR to extract certain tools from its archive. \* Certutil leveraged for payload download.                                                                                                                                                                                                                                                                                                                                                             |
| Persistence         | Multiple scheduled tasks were set up for hourly execution of different commands.                                                                                                                                                                                                                                                                                                                                                                           |
| Credential access   | We observed the presence of tools such as Mimikatz and Impacket-based executables, primarily used for extracting credentials.                                                                                                                                                                                                                                                                                                                              |
| Discovery           | \* Execution of [ADRecon](https://github.com/sense-of-security/ADRecon) PowerShell script to gather information and extract artifacts from a given Active Directory, and a [Rubeus](https://attack.mitre.org/software/S1071/) based executable. \* Some of the tools or built-in commands attackers used were *wmic, nslookup, ping, ipconfig, net, quser, qwinsta* and [SoftPerfect Network Scanner](https://www.softperfect.com/products/networkscanner/). |
| Command and control | \* Reverse tunnel with adversary server via SSH \* PowerShell command to send the victim IP address and hostname to a given hard-coded domain, via POST request. \* Multiple other tools were used in this scenario, including *Plink, GOST* and a *SOCKS* proxy tool.                                                                                                                                                                                        |

As previously mentioned, it is unclear how the Repellent Scorpius group possessed this data. However, we observed certain overlaps with another attack carried out by an affiliate that deployed BlackCat ransomware, [reported](https://blog.talosintelligence.com/from-blackmatter-to-blackcat-analyzing/) in March 2022.

Examples include attackers using ADRecon and SoftPerfect Network Scanner tools, setting up a reverse SSH tunnel and creating similar scheduled tasks. That said, there was no evidence that BlackCat was deployed in this incident, likely due to the fact that different stages of the attack were thwarted.

While we did come across a few filename-based overlaps, we observed no substantial TTP overlaps between the recent ransomware incident and the historical one.

## New Version of Encryptor

Unit 42 researchers found an updated Cicada3301 encryptor in late July 2024, which had some differences from the previously analyzed version.

Threat authors added a new command-line argument, --no-note. When this argument is invoked, the encryptor will not write the ransom note to the system.

Instead of running the embedded PsExec binary directly via PowerShell, the encryptor will create a randomly named .bat file in the C:\\Users\\Public directory, which executes using "cmd.exe /C". Included in the created .bat file is a line to delete the script after execution is complete.

The most recent samples do not have hard-coded usernames or passwords in the binary but still retain the capability to execute PsExec using these credentials if they exist.

An example of the script is below:  
C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\\<encryptor\>.exe" --no\_impl --key \<key\> -p \<path\> del /Q "C:\\Users\\Public\\\<random\_10\_chars\>.bat"

|-------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | C:\\Users\\Public\\psexec0.exe -accepteula -s -d "C:\\Users\\Public\\\<encryptor\>.exe" --no\_impl --key \<key\> -p \<path\> del /Q "C:\\Users\\Public\\\<random\_10\_chars\>.bat" |

Finally, the ransomware developers modified the methods used to stop services and added a PowerShell command to forcibly stop all running virtual machines (VMs) on the target system.

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|
| **Command**                                                                                                                                                         | **Action**                                                                                                                    |
| powershell -Command "$excludedVMs = @(); Get-VM | Where-Object { $_.Name -notin $excludedVMs } | ForEach-Object { Stop-VM -Name $_.Name -Force -Confirm:$false }" | Forcibly stops all running VMs. VM files that are not shut down before encryption are permanently damaged.                    |
| for /F "tokens=2 delims=:" %i in ('sc query state^= all ^| findstr /I \<service\_name\>) do sc stop %i                                                            | Stops all services containing the supplied service name.                                                                      |
| cmd /C "net stop \<serviceName\> /y"                                                                                                                                | Uses the net command to stop a running service. We list new services that the threat stops using this method in the appendix. |

## Conclusion

Although it may not currently appear to be widespread, Repellent Scorpius is actively hiring IAB and network intruders. It has also recently set up a RaaS affiliate program. Therefore, we can expect to see attackers posting a growing list of active incidents and victims on their leak site in the near future.

The TTPs highlighted here are from specific incident response engagements. Considering that the Cicada3301 ransomware is relatively new, we expect that its TTPs will change and evolve over time.

## Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* The Cicada3301 ransomware is detected and prevented by [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR).
* [Advanced WildFire](https://docs.paloaltonetworks.com/advanced-wildfire) identifies all known samples mentioned in this article as malicious.
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/how-url-filtering-works) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security/administration/about-dns-security) identify known URLs and domains associated with this activity as malicious.
* Prisma Cloud can detect known Cicada3301 ransomware binaries executed within cloud environments through the [Cloud Security Agent (CSA)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Pairing-Prisma-Cloud-Compute-with-Cortex-XDR).

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### Hashes

|------------------------------------------------------------------|--------------------------------------------------------------------------------|
| 8ec114b29c7f2406809337b6c68ab30b0b7f0d1647829d56125e84662b84ea74 | Cicada3301 encryptor                                                           |
| 0260258f6f083aff71c7549a6364cb05d54dd27f40ca1145e064353dd2a9e983 | Batch script 1.bat containing multiple Cicada3301 encryptor execution commands |
| 2d73b3aefcfbb47c1a187ddee7a48a21af7c85eb49cbdcb665db07375e36dc33 | Cicada3301 encryptor                                                           |
| 3969e1a88a063155a6f61b0ca1ac33114c1a39151f3c7dd019084abd30553eab | Cicada3301 encryptor new variant                                               |
| 56e1d092c07322d9dad7d85d773953573cc3294b9e428b3bbbaf935ca4d2f7e7 | Cicada3301 encryptor new variant                                               |

### Infrastructure

* 103\.42.240\[.\]37
* 91\.238.181\[.\]238
* cicadabv7vicyvgz5khl7v2x5yygcgow7ryy6yppwmxii4eoobdaztqd\[.\]onion/

## Appendix

[Appendix for Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware](https://github.com/PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information/blob/main/cicada3301_appendix.txt) -- GitHub, Palo Alto Networks

## Additional Resources

* [Cicada 3301](https://en.wikipedia.org/wiki/Cicada_3301) -- Wikipedia
* [The internet mystery that has the world baffled](https://web.archive.org/web/20131125232546/http://www.telegraph.co.uk/technology/internet/10468112/The-internet-mystery-that-has-the-world-baffled.html) -- The Telegraph
* [C0015, Campaign C0015](https://attack.mitre.org/campaigns/C0015/) -- MITRE ATT\&CK
* [CONTInuing the Bazar Ransomware Story](https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/) -- The DFIR Report
* [Threat Brief: ConnectWise ScreenConnect Vulnerabilities (CVE-2024-1708 and CVE-2024-1709)](https://unit42.paloaltonetworks.com/connectwise-threat-brief-cve-2024-1708-cve-2024-1709/) -- Unit 42, Palo Alto Networks

Back to top

### Tags

* [ALPHV](https://unit42.paloaltonetworks.com/tag/alphv/ "ALPHV")
* [Ambitious Scorpius](https://unit42.paloaltonetworks.com/tag/ambitious-scorpius/ "Ambitious Scorpius")
* [Bashful Scorpius](https://unit42.paloaltonetworks.com/tag/bashful-scorpius/ "Bashful Scorpius")
* [BlackCat ransomware](https://unit42.paloaltonetworks.com/tag/blackcat-ransomware/ "BlackCat ransomware")
* [Cicada3301](https://unit42.paloaltonetworks.com/tag/cicada3301/ "Cicada3301")
* [CVE-2024-1708](https://unit42.paloaltonetworks.com/tag/cve-2024-1708/ "CVE-2024-1708")
* [CVE-2024-1709](https://unit42.paloaltonetworks.com/tag/cve-2024-1709/ "CVE-2024-1709")
* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")
* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")
* [Nokoyawa](https://unit42.paloaltonetworks.com/tag/nokoyawa/ "Nokoyawa")
* [RaaS](https://unit42.paloaltonetworks.com/tag/raas/ "RaaS")
* [Repellent Scorpius](https://unit42.paloaltonetworks.com/tag/repellent-scorpius/ "Repellent Scorpius")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Assessment: North Korean Threat Groups](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/ "Threat Assessment: North Korean Threat Groups")

### Table of Contents

* 

### Related Articles

* [The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version](https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ "article - table of contents")
* [No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "article - table of contents")
* [Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ "article - table of contents")

## Related Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
