CACTUSTORCH

First seen
2017-01-01 00:00:00
Malware type
trojan, loader
Profile updated
2026-07-07 12:53:15

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher. It will spawn a 32 bit version of the binary specified and inject shellcode into it.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_HKTL_NET_NAME_CACTUSTORCH (yara-rule)

Reports & references

  • Microsoft — Gadolinium Detecting Empires Cloud (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Cactustorch (report)
  • seqrite.com — Seqrite Whitepaper Operation Sidecopy (report)
  • macnica.net — Mpression Automobile (report)
  • github.com — Cactustorch (report)
  • codercto.com — 46729 (report)
  • forensicitguy.github.io — Analyzing Cactustorch Hta Cobaltstrike (report)

External references