cactus

First seen
2023-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-05-24 02:57:10
Profile updated
2026-07-07 12:57:21

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical professional-services

Context

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox. As mentioned earlier, the ransomware especially exploits vulnerabilities in VPNs, also utilizing obfuscation techniques to conceal its activities, such as employing UPX and utilizing encryption algorithms like OpenSSL, AES OCB, ChaCha20_Poly1305, system reinitializations, and others.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cactus_Auto (yara-rule)

Reports & references

  • x.com — 1730383711437283757 (report)
  • twitter.com — 1730383711437283757 (report)
  • blog.sekoia.io — Sekoia Io Mid 2023 Ransomware Threat Landscape (report)
  • ransomlook.io — Cactus (report)
  • kroll.com — Cactus Ransomware Prickly New Variant Evades Detection (report)
  • socradar.io — Dark Web Profile Cactus Ransomware (report)
  • securityscorecard.com — Whitepaper Cactus Ransomware (report)
  • thehackernews.com — Cactus Ransomware Exploits Qlik Sense (report)
  • sentinelone.com — Cactus Ransomware (report)
  • blog.barracuda.com — Who Is Behind Cactus Ransomware (report)
  • kroll.com — Cactus Ransomware Prickly New Variant Evades Detection (report)
  • tripwire.com — Cactus Ransomware What You Need Know (report)
  • Trend Micro — Black Basta Cactus Ransomware Backconnect (report)
  • intrinsec.com — Tlp Clear 31072025 Shadowsyndicate Infrastructure Illumination En (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cactus (report)
  • shadowstackre.com — Cactus (report)

External references