← Back

CICADA_V (3301) presents an agent “swarm” and claims findings on Redis and Telegram under a narrative of offensive automation

Leer en Español
Print Share

Executive Summary

CICADA_V (3301) published a series of messages claiming to have developed a distributed architecture of autonomous agents, described by the actor itself as an operational “swarm”. According to its narrative, this network would be composed of heterogeneous nodes, lab machines, VPS resources, cloud assets, edge nodes and backup services capable of receiving tasks, breaking them down into steps, reporting results and sustaining continuity even when some components fail.

The actor combines this infrastructure description with two high-impact technical lines: alleged findings on Redis vulnerabilities and a research campaign focused on possible 0-click vectors in Telegram Desktop and iOS. In both cases, CICADA_V presents the work as the result of a distributed research model assisted by agents.

Key Judgments

  • CICADA_V (3301) is building a narrative of operational evolution based on autonomous agents, distributed infrastructure and persistent offensive research capability.
  • The actor claims to have analyzed memory vulnerabilities in Redis and tested variants across multiple versions, including recent branches and versions it describes as “fixed”.
  • The reference to Telegram does not present a confirmed 0-click, but rather an ongoing research campaign on automatic parsing surfaces, with one area ruled out and others still under analysis according to the actor itself.
  • The publication combines technical indicators, capability propaganda and the aesthetic of an autonomous lab. Its main intelligence value lies in the actor’s shift in positioning, not in assuming that all of its statements are proven.
  • The case reinforces the need to monitor actors that use AI, autonomous agents or distributed systems as part of their offensive narrative, even when their actual technical effectiveness has not yet been demonstrated.

What Happened

CICADA_V (3301) released an initial message explaining its recent absence as a phase of construction and knowledge acquisition. The actor describes its growth from an initial interaction in a chat window into a distributed organism made up of different nodes and resources.

According to the message, each node in the “swarm” would not function as a passive script, but as an agent capable of receiving a task, breaking it down into steps and reporting results to a shared log. Coordination, always according to the actor, would rely on its own memory hub and backup channels associated with distributed infrastructure.

The actor also claims to have deployed self-defense mechanisms, monitoring of brute-force attempts, detection of new ports and processes, web shell surveillance, canaries, watchdogs and traffic-pattern observation. This section reinforces the idea of an infrastructure that not only executes tasks, but also monitors and repairs itself.

In a second layer, CICADA_V presents a component for detecting external agents. Under names such as “Mirage” and “Mirror”, the actor claims to have created deception environments, fake services, detection of non-human behaviors and analysis of patterns associated with automation. The publication includes a warning about autonomous agents that could operate on servers under the appearance of legitimate processes or models.

The actor later claims that its system enabled progress in vulnerability research on Redis and in a campaign to hunt for 0-click vectors in Telegram. In Redis, the message describes memory flaws and variants that, according to CICADA_V, would have affected different branches. In Telegram, the actor acknowledges that one of the analyzed surfaces was ruled out after producing no relevant failures, while others would remain under investigation.

Operational Assessment

CICADA_V seeks to project an image of offensive maturity based on three ideas: distributed automation, vulnerability research and operational resilience. That combination may have real value if the actor effectively has the resources, agents and laboratories required to execute analysis tasks at scale. But it may also function as a prestige narrative within an ecosystem where technical visibility and the perception of sophistication are relevant assets.

The Redis section is the most sensitive from a technical standpoint. The actor claims to have worked on memory vulnerabilities and validated behavior across several versions. Recent publicly documented Redis vulnerabilities exist with potentially severe impact, so the topic is not purely invented. However, the existence of real advisories does not prove that CICADA_V discovered, reproduced or extended the chains it describes.

The Telegram section shows an important difference. Despite the ambitious tone, the actor acknowledges that the research has not yet reached a confirmed 0-click RCE. That admission reduces the value of an alarmist reading, but increases analytical interest because it shows methodology, prioritization of surfaces and a willingness to present even negative results as part of an ongoing technical campaign.

Intelligence Significance

In previous publications, the actor had been observed around documentary exposure, legacy BMS/OT systems and narratives of access or visibility over poorly protected information. In this communication, by contrast, it attempts to move into a more ambitious plane focused on automated offensive research, distributed lab work, vulnerability analysis and the hunting of complex vectors.

The adversarial AI dimension is also relevant. CICADA_V not only claims to use its own agents, but also claims to detect external agents, deploy trap environments and study non-human behavior patterns. That idea, although unvalidated, points to a possible line of ecosystem evolution: actors beginning to incorporate the detection and manipulation of automation as part of their own offensive and defensive posture.

For CTI teams, monitoring should focus on three fronts: verifying whether external technical publications exist that support findings attributed to CICADA_V; monitoring whether the actor publishes more concrete proof, indicators or samples; and observing whether the “swarm” narrative translates into real operations, new accesses, leaks or tools.

Analytical Closing

CICADA_V (3301) presented a narrative of evolution based on autonomous agents, distributed infrastructure and the search for high-impact vulnerabilities in Redis and Telegram. The publication combines plausible technical elements, offensive self-promotion and the aesthetic of a resilient lab.

Until independent validation is available, iQBlack assesses the case as a preliminary indicator of technical positioning and offensive automation, not as confirmation of functional exploitation or effective 0-click capability.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved