A new double-extortion ransomware variant, Cicada3301, targets VMware ESXi servers by brute-forcing credentials, encrypting data using the ChaCha20 cipher, then using ScreenConnect for remote access, with a method similar to ALPHV/BlackCat, affecting industries like healthcare and manufacturing across North America and England, while Truesec and Morphisec have identified links to the Brutus botnet and previous ransomware groups.
















