Discovery Enum
- Nmap
- SoftPerfect NetScan
Cactus is a Windows ransomware family and ransomware-as-a-service operation first identified in March 2023.
Profile source: Mallory opens in a new tabCACTUS
Cactus is a Windows ransomware family and ransomware-as-a-service operation first identified in March 2023. It encrypts victim data using per-file AES encryption protected by an embedded RSA public key, supports configurable encryption scope and threading, and can partially encrypt large files to accelerate impact. Encrypted files receive Cactus-specific extensions and the malware deploys a ransom note.
Cactus supports persistence through scheduled tasks, enumerates local and attached drives, avoids selected operating-system and application directories, and uses Restart Manager functionality to identify processes locking target files. Operators have also been observed deleting evidence, deploying remote-administration tools, creating unauthorized accounts, establishing reverse-shell access, performing endpoint and network reconnaissance, moving laterally, archiving data, and exfiltrating victim data before encryption. The operation is associated with double extortion.
Observed intrusions have exploited unpatched internet-exposed Qlik Sense Enterprise servers, including CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365. Other Cactus-linked campaigns used spam flooding, Microsoft Teams voice phishing, and social engineering to persuade targets to grant access through Microsoft Quick Assist. Cactus activity has affected critical infrastructure, manufacturing, construction, and Dutch organizations among other sectors. Reporting identifies operational and tradecraft overlap with Black Basta, including apparent migration of some former Black Basta affiliates to Cactus.
466a8e120c75770ecbc0c73f0439d304718d56fd19bbaf5e78c03e096dae64ca586a7991bb097e7c4ef676b180f65a6a7fa55bf92073ca2115d70641566ce89bccb993b425257228bd48c0aac20d502728103f745f58a2af71d327012846c02242bce02c8f6d561f02856a367272b83582cb0577a64e59d187ab3174d1095c2236330349aa9c3dc0fee84e0c57283e651773e21117bd6a0e17a3975be84ab6aeReported operators
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.
Since November 2023, the Cactus ransomware group has been actively targeting vulnerable Qlik Sense servers.
Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.