Skip to content

CACTUS

Cactus is a Windows ransomware family and ransomware-as-a-service operation first identified in March 2023.

Profile source: Mallory opens in a new tab

CACTUS

Family profile

Cactus is a Windows ransomware family and ransomware-as-a-service operation first identified in March 2023. It encrypts victim data using per-file AES encryption protected by an embedded RSA public key, supports configurable encryption scope and threading, and can partially encrypt large files to accelerate impact. Encrypted files receive Cactus-specific extensions and the malware deploys a ransom note.

Cactus supports persistence through scheduled tasks, enumerates local and attached drives, avoids selected operating-system and application directories, and uses Restart Manager functionality to identify processes locking target files. Operators have also been observed deleting evidence, deploying remote-administration tools, creating unauthorized accounts, establishing reverse-shell access, performing endpoint and network reconnaissance, moving laterally, archiving data, and exfiltrating victim data before encryption. The operation is associated with double extortion.

Observed intrusions have exploited unpatched internet-exposed Qlik Sense Enterprise servers, including CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365. Other Cactus-linked campaigns used spam flooding, Microsoft Teams voice phishing, and social engineering to persuade targets to grant access through Microsoft Quick Assist. Cactus activity has affected critical infrastructure, manufacturing, construction, and Dutch organizations among other sectors. Reporting identifies operational and tradecraft overlap with Black Basta, including apparent migration of some former Black Basta affiliates to Cactus.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Reconnaissance

Operational record

51
Indicators
1
YARA rules
6
Ransom notes
2
Leak sites
0 available

Discovery Enum

  • Nmap
  • SoftPerfect NetScan

Exfiltration

  • RClone

Networking

  • Chisel

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk
  • Splashtop
  • SuperOps

Published indicators

Md5

50 total
  • 466a8e120c75770ecbc0c73f0439d304
  • 718d56fd19bbaf5e78c03e096dae64ca
  • 586a7991bb097e7c4ef676b180f65a6a
  • 7fa55bf92073ca2115d70641566ce89b
  • ccb993b425257228bd48c0aac20d5027
  • 28103f745f58a2af71d327012846c022
  • 42bce02c8f6d561f02856a367272b835
  • 82cb0577a64e59d187ab3174d1095c22
  • 36330349aa9c3dc0fee84e0c57283e65
  • 1773e21117bd6a0e17a3975be84ab6ae

Reported operators

Threat actors

4 named in public reporting
ShadowSyndicate

It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.

ToyMaker

TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.

CACTUS

Since November 2023, the Cactus ransomware group has been actively targeting vulnerable Qlik Sense servers.

Black Basta

Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.

Exploited software

Vulnerabilities linked to CACTUS

7 CVEs

MITRE ATT&CK

CACTUS in ATT&CK

27 distinct techniques

Reporting

Research mentioning CACTUS

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.