Overview

Platforms: Windows
Variants: —
Extensions: .cts · .cts0 · .cts1 · .cts2
ATT&CK software: Cobalt Strike · Chisel · BackConnect
Initial access: Exploit Public-Facing Application
Top countries: —
Observed sectors: Manufacturing · Professional Services · Technology · Construction · Transportation & Logistics
Tracked victims: 242

Victims

ASSA ABLOY CLAIMED
March 17, 2025 Sweden Manufacturing
Manufacturing organization in Sweden.
KYB Corporation CLAIMED
March 17, 2025 Automotive
Automotive organization.
Urban One CLAIMED
March 17, 2025 United States Media & Entertainment
Media & Entertainment organization in United States.
Tempel Steel Company CLAIMED
March 17, 2025 United States Manufacturing
Manufacturing organization in United States.
CHF Industries CLAIMED
March 14, 2025 United States Manufacturing
Manufacturing organization in United States.
Show more victims (12)
Quigley Eye Specialists CLAIMED
March 11, 2025 United States Healthcare
Healthcare organization in United States.
American International Industries CLAIMED
March 10, 2025 United States Consumer Products
Consumer Products organization in United States.
Forman Mills CLAIMED
March 10, 2025 United States Retail & E-Commerce
Retail & E-Commerce organization in United States.
Amalgamated Sugar Company CLAIMED
March 10, 2025 United States Agriculture & Food
Agriculture & Food organization in United States.
Pace Logistics CLAIMED
March 10, 2025 United States Transportation & Logistics
Transportation & Logistics organization in United States.
Steel Warehouse CLAIMED
March 10, 2025 United States Manufacturing
Manufacturing organization in United States.
Caltrol CLAIMED
March 10, 2025 United States Professional Services
Professional Services organization in United States.
Grede CLAIMED
March 7, 2025 United States Manufacturing
Manufacturing organization in United States.
Associated Asset Management CLAIMED
March 7, 2025 United States Construction
Construction organization in United States.
ElectroCraft CLAIMED
March 6, 2025 United States Manufacturing
Manufacturing organization in United States.
Almost Famous Clothing CLAIMED
March 4, 2025 United States Manufacturing
Manufacturing organization in United States.
Everel Group CLAIMED
March 4, 2025 Italy Technology
Technology organization in Italy.

Operational Activity

Recent Observations

Initial Access via Qlik Sense Vulnerabilities
November 2023
Arctic Wolf Labs observed CACTUS ransomware intrusions exploiting publicly exposed Qlik Sense installations for initial access, including exploitation associated with CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365.
Credential Access via Credential Dumping and Browser Data
CACTUS actors have been observed obtaining credentials through OS credential dumping and extracting stored credentials from web browsers to support further access within compromised environments.
Lateral Movement via RDP and Remote Management Tools
November 2023
CACTUS actors have been observed using valid or newly created accounts with Remote Desktop Protocol (RDP), as well as remote management tooling such as SuperOps, for lateral movement.
Exfiltration via Rclone
November 2023
Cactus actors utilize Rclone for the exfiltration of sensitive data to cloud storage providers prior to the deployment of ransomware.
Disabling Security Software
November 2023
To facilitate ransomware deployment, the actors employ batch scripts designed to identify and terminate processes associated with antivirus and security monitoring software.

TTPs

ATT&CK coverage: 5 techniques
T1190 Exploit Public-Facing Application
VERIFIED
Cactus ransomware operators gain initial access by exploiting vulnerabilities in public-facing applications, specifically targeting Fortinet VPN devices.
T1059.001 Command and Scripting Interpreter: PowerShell
PROBABLE
Actors use PowerShell scripts for various stages of the attack, including the deployment of payloads and execution of malicious commands.
T1027 Obfuscated Files or Information
VERIFIED
Cactus ransomware employs custom 7-Zip archives and obfuscated batch scripts to evade detection during the staging and deployment phases.
Show more TTPs (2)
T1562.001 Impair Defenses: Disable or Modify Tools
VERIFIED
The group utilizes batch scripts to terminate and uninstall security software (AV/EDR) prior to executing the encryption process.
T1486 Data Encrypted for Impact
VERIFIED
Cactus uses a custom ransomware binary to encrypt files on the victim network, often using a combination of AES and RSA encryption.

CVEs

HTTP tunneling vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since: November 2023
Path traversal vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since: November 2023
HTTP tunneling vulnerability in Qlik Sense Enterprise for Windows that can be leveraged for remote code execution.
Associated since: November 2023

Infrastructure

Data Leak Site (DLS)
Public data-leak and extortion infrastructure associated with the Cactus ransomware operation.
Tox contact
Cactus actors have used the Tox peer-to-peer messaging service for victim extortion and negotiation.

Attribution

Relationships

ToyMaker VERIFIED
Reported RaaS relationship
ToyMaker, an initial access broker, has been documented handing over network access to Cactus ransomware affiliates to conduct double-extortion operations.
UNC2198 PROBABLE
Reported RaaS relationship
The threat actor UNC2198 was observed deploying Cactus ransomware in November 2023.

Affiliates

No affiliate information available.

Timeline

2023-05-10
Kroll publishes technical analysis of CACTUS
Kroll documented CACTUS tradecraft including the use of tools such as Chisel and Rclone, scheduled tasks, account enumeration and custom scripts used during ransomware deployment.
2023-03
Cactus ransomware observed in the wild
Kroll identified CACTUS ransomware activity dating to at least March 2023. The ransomware encryptor requires a key to decrypt its own binary before execution, a technique likely intended to reduce antivirus detection.

Sources