Overview
Platforms:
Windows
Variants:
—
Extensions:
.cts · .cts0 · .cts1 · .cts2
ATT&CK software:
Cobalt Strike · Chisel · BackConnect
Initial access:
Exploit Public-Facing Application
Top countries:
—
Observed sectors:
Manufacturing · Professional Services · Technology · Construction · Transportation & Logistics
Tracked victims:
242
Victims
ASSA ABLOY
CLAIMED
Manufacturing organization in Sweden.
KYB Corporation
CLAIMED
Automotive organization.
Urban One
CLAIMED
Media & Entertainment organization in United States.
Tempel Steel Company
CLAIMED
Manufacturing organization in United States.
CHF Industries
CLAIMED
Manufacturing organization in United States.
Show more victims (12)
Quigley Eye Specialists
CLAIMED
Healthcare organization in United States.
American International Industries
CLAIMED
Consumer Products organization in United States.
Forman Mills
CLAIMED
Retail & E-Commerce organization in United States.
Amalgamated Sugar Company
CLAIMED
Agriculture & Food organization in United States.
Pace Logistics
CLAIMED
Transportation & Logistics organization in United States.
Steel Warehouse
CLAIMED
Manufacturing organization in United States.
Caltrol
CLAIMED
Professional Services organization in United States.
Grede
CLAIMED
Manufacturing organization in United States.
Associated Asset Management
CLAIMED
Construction organization in United States.
ElectroCraft
CLAIMED
Manufacturing organization in United States.
Almost Famous Clothing
CLAIMED
Manufacturing organization in United States.
Everel Group
CLAIMED
Technology organization in Italy.
Operational Activity
Recent Observations
Initial Access via Qlik Sense Vulnerabilities
November 2023
Arctic Wolf Labs observed CACTUS ransomware intrusions exploiting publicly exposed Qlik Sense installations for initial access, including exploitation associated with CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365.
Credential Access via Credential Dumping and Browser Data
CACTUS actors have been observed obtaining credentials through OS credential dumping and extracting stored credentials from web browsers to support further access within compromised environments.
Lateral Movement via RDP and Remote Management Tools
November 2023
CACTUS actors have been observed using valid or newly created accounts with Remote Desktop Protocol (RDP), as well as remote management tooling such as SuperOps, for lateral movement.
Exfiltration via Rclone
November 2023
Cactus actors utilize Rclone for the exfiltration of sensitive data to cloud storage providers prior to the deployment of ransomware.
Disabling Security Software
November 2023
To facilitate ransomware deployment, the actors employ batch scripts designed to identify and terminate processes associated with antivirus and security monitoring software.
TTPs
ATT&CK coverage:
5 techniques
T1190
Exploit Public-Facing Application
VERIFIEDCactus ransomware operators gain initial access by exploiting vulnerabilities in public-facing applications, specifically targeting Fortinet VPN devices.
T1059.001
Command and Scripting Interpreter: PowerShell
PROBABLEActors use PowerShell scripts for various stages of the attack, including the deployment of payloads and execution of malicious commands.
T1027
Obfuscated Files or Information
VERIFIEDCactus ransomware employs custom 7-Zip archives and obfuscated batch scripts to evade detection during the staging and deployment phases.
Show more TTPs (2)
T1562.001
Impair Defenses: Disable or Modify Tools
VERIFIEDThe group utilizes batch scripts to terminate and uninstall security software (AV/EDR) prior to executing the encryption process.
T1486
Data Encrypted for Impact
VERIFIEDCactus uses a custom ransomware binary to encrypt files on the victim network, often using a combination of AES and RSA encryption.
CVEs
HTTP tunneling vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since:
November 2023
Path traversal vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since:
November 2023
HTTP tunneling vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since:
November 2023
Infrastructure
Data Leak Site (DLS)
Public data-leak and extortion infrastructure associated with the Cactus ransomware operation.
Tox contact
Cactus actors have used the Tox peer-to-peer messaging service for victim extortion and negotiation.
Attribution
Relationships
ToyMaker
VERIFIED
Reported RaaS relationship
ToyMaker, an initial access broker, has been documented handing over network access to Cactus ransomware affiliates to conduct double-extortion operations.
UNC2198
PROBABLE
Reported RaaS relationship
The threat actor UNC2198 was observed deploying Cactus ransomware in November 2023.
Affiliates
No affiliate information available.
Timeline
2023-05-10
Kroll publishes technical analysis of CACTUS
Kroll documented CACTUS tradecraft including the use of tools such as Chisel and Rclone, scheduled tasks, account enumeration and custom scripts used during ransomware deployment.
2023-03
Cactus ransomware observed in the wild
Kroll identified CACTUS ransomware activity dating to at least March 2023. The ransomware encryptor requires a key to decrypt its own binary before execution, a technique likely intended to reduce antivirus detection.
Sources
Show more sources (7)
A Deep Dive into Cactus Ransomware
SecurityScorecard
Ransomware Tracker
WatchGuard Technologies
Cactus victim claim tracking
RansomLook
Cactus victim claim tracking
RansomFeed