Skip to main content
Mallory

Sicarii

Also known assicarii

Sicarii is a ransomware-as-a-service (RaaS) operation that emerged in late 2025, with reporting placing its appearance in December 2025. It presents itself as an Israeli/Jewish-affiliated group, using Hebrew language, Israeli/Jewish symbolism, and references to historical Jewish groups, but multiple reports assess this identity as likely false-flag or performative. Check Point reported that Sicarii’s underground activity and affiliate recruitment are primarily conducted in Russian, that its Hebrew content appears machine-translated or non-native, and that the operators appear to be Russian speakers. The operation has also been described as immature, centralized, and inconsistent in its public claims. Technically, Sicarii is a functional ransomware threat with data theft, credential theft, reconnaissance, persistence, and destructive capabilities. Reported behavior includes anti-virtualization checks, internet connectivity checks, network reconnaissance via ARP and RDP scanning, credential and application-data theft, exfiltration of collected data, persistence via registry changes and service creation, and file encryption using AES-GCM with the .sicarii extension. Reporting also states the malware can target Fortinet devices, including attempted exploitation of CVE-2025-64446 for lateral movement. Additional reported capabilities include collection of browser, messaging-app, wallet, and system data; LSASS dumping; and deployment of a startup batch script such as destruct.bat to corrupt boot components, wipe disks, and force shutdown. A defining characteristic of Sicarii is a critical cryptographic flaw: the malware generates fresh key material during execution and discards the corresponding private key, making decryption impossible for victims and operators alike. Multiple sources describe this as rendering ransom payment ineffective and making the malware closer to destructive pseudo-ransomware or “destruction-ware” than conventional ransomware. Halcyon assessed with moderate confidence that AI-assisted tooling may have contributed to the poor implementation. Sicarii has been described as mainly targeting entities in the Middle East, Turkey, and Africa region, with one reported US-based victim. It has also been reported to market itself as targeting Arab and Muslim countries while avoiding Israeli systems, and its malware includes geo-fencing checks intended to prevent execution on Israeli hosts. In March 2026, Halcyon reported that Sicarii administrator Uke said the operation could not keep up with affiliate demand and urged pro-Iranian operators to move to Baqiyat 313 Locker, also known as BQTlock. Sicarii and BQTlock were described as separate RaaS platforms used by pro-Palestinian and pro-Iranian regime-affiliated operators.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics38 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1133
External Remote Services
TA0002
Execution
3 techniques
T1047
Windows Management Instrumentation
T1059
Command and Scripting Interpreter
T1129
Shared Modules
TA0003
Persistence
2 techniques
T1133
External Remote Services
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0004
Privilege Escalation
3 techniques
T1134
Access Token Manipulation
T1543
Create or Modify System Process
T1543.003
Windows Service
T1548
Abuse Elevation Control Mechanism
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1070
Indicator Removal
T1134
Access Token Manipulation
TA0112
Defense Impairment
1 technique
T1222
File and Directory Permissions Modification
TA0006
Credential Access
4 techniques
T1003
OS Credential Dumping
T1056
Input Capture
T1539
Steal Web Session Cookie
T1552
Unsecured Credentials
TA0007
Discovery
9 techniques
T1007
System Service Discovery
T1033
System Owner/User Discovery
T1057
Process Discovery
T1082
System Information Discovery
T1083
File and Directory Discovery
T1087
Account Discovery
T1135
Network Share Discovery
T1518
Software Discovery
T1614
System Location Discovery
TA0009
Collection
4 techniques
T1005
Data from Local System
T1056
Input Capture
T1074
Data Staged
T1114
Email Collection
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1573
Encrypted Channel
TA0040
Impact
3 techniques
T1485×3
Data Destruction
T1486×3
Data Encrypted for Impact
T1489
Service Stop
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping34

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.