cactus
Group profile
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs
MITRE ATT&CK TTPs
Initial Access
T1190Exploit Public-Facing Application
The group exploits vulnerabilities in VPN applications.
Execution
Persistence
T1136Create Account
The group creates a service/system account to launch the ransomware.
Defense Evasion
T1027Obfuscated Files or Information
The group uses file obfuscation techniques to avoid detection by defenses.
T1027.002Obfuscated Files or Information: Software Packing
Actors use packing in ransomware payload to avoid detection by defenses.
T1562.001Disable or Modify Tools
The group uses modification and disabling of security tools to avoid possible malware and access detection.
Credential Access
Discovery
T1018Remote System Discovery
Actors attempt to obtain a list of other systems, hosts, IPs, and any other identifier for lateral movement.
T1049System Network Connections Discovery
Actors use tools to scan the organization's infrastructure systems.
T1087Account Discovery
Actors attempt to obtain a list of accounts, user names, and valid email addresses for later access.
T1087.002Account Discovery: Domain Account
Actors use scripts to identify domain accounts of connected users through Windows event logs.
Lateral Movement
Exfiltration
T1567.002Exfiltration to Cloud Storage
Actors exfiltrate data to a cloud storage service through tools such as Rclone and others.
Command and Control
Impact
T1486Data Encrypted for Impact
Actors use ransomware payload to encrypt data and change extensions.
Resource Development
T1538.008Malvertising
The threat actor was identified by Microsoft as responsible for the Danabot campaign via malvertising for final delivery of Ransomware Cactus.
Recent victims
showing 50 of 248| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2024-12-25 | optiline.comoptiline.com | Construction | EE |
| 2024-12-16 | fplfood.comfplfood.com | Agriculture and Food Production | US |
| 2025-01-09 | biagibros.combiagibros.com | Transportation/Logistics | US |
| 2025-03-17 | assaabloy.comassaabloy.com | Manufacturing | SE |
| 2025-03-17 | kyb.comkyb.com | Technology | JP |
| 2025-02-09 | tempel.comtempel.com | Technology | US |
| 2025-02-12 | thermoid.comthermoid.com | Manufacturing | US |
| 2025-03-12 | baillie.combaillie.com | Construction | US |
| 2025-02-25 | urban1.comurban1.com | Technology | US |
| 2025-02-26 | rocketstores.comrocketstores.com | Consumer Services | US |
| 2025-03-03 | quigleyeye.comquigleyeye.com | Healthcare | US |
| 2025-01-30 | stanleyconsultants.comstanleyconsultants.com | Business Services | US |
| 2025-02-06 | caltrol.comcaltrol.com | Technology | US |
| 2025-01-30 | holtcat.comholtcat.com | Manufacturing | US |
| 2025-02-06 | alphabaking.comalphabaking.com | Agriculture and Food Production | US |
| 2025-02-17 | bluedge.combluedge.com | Technology | US |
| 2025-02-25 | lifting.comlifting.com | Manufacturing | US |
| 2025-02-24 | chfindustries.comchfindustries.com | Manufacturing | US |
| 2025-02-06 | aiibeauty.comaiibeauty.com | Consumer Services | US |
| 2025-02-06 | formanmills.comformanmills.com | Consumer Services | US |
| 2025-02-06 | amalgamatedsugar.comamalgamatedsugar.com | Agriculture and Food Production | US |
| 2025-02-12 | everelgroup.comeverelgroup.com | Manufacturing | IT |
| 2025-02-16 | regulvar.comregulvar.com | Construction | CA |
| 2025-01-30 | electrocraft.comelectrocraft.com | Technology | US |
| 2025-02-06 | associatedasset.comassociatedasset.com | Financial Services | US |
| 2025-02-06 | grede.comgrede.com | Manufacturing | US |
| 2025-02-24 | branchgroup.combranchgroup.com | Construction | US |
| 2025-02-06 | pace-usa.compace-usa.com | Transportation/Logistics | US |
| 2024-01-17 | steelwarehouse.comsteelwarehouse.com | Manufacturing | US |
| 2025-01-21 | newhorizonsbaking.comnewhorizonsbaking.com | Agriculture and Food Production | US |
| 2025-02-05 | uniekinc.comuniekinc.com | Manufacturing | US |
| 2025-01-16 | midwayimporting.commidwayimporting.com | Consumer Services | US |
| 2025-01-15 | revitalash.comrevitalash.com | Consumer Services | US |
| 2025-02-03 | bestbrands.combestbrands.com | Consumer Services | US |
| 2025-01-14 | kinseysinc.comkinseysinc.com | Manufacturing | US |
| 2025-02-05 | steelerubber.comsteelerubber.com | Manufacturing | US |
| 2025-02-05 | almostfamousclothing.comalmostfamousclothing.com | Consumer Services | US |
| 2025-02-17 | T This entry has been removed following a request from the company. | Consumer Services | US |
| 2025-02-05 | ssmcoop.comssmcoop.com | Agriculture and Food Production | US |
| 2025-01-21 | curtisint.comcurtisint.com | Technology | CA |
| 2025-02-12 | britannicahome.combritannicahome.com | Consumer Services | US |
| 2025-01-29 | uniquehd.comuniquehd.com | Manufacturing | US |
| 2024-01-17 | northernresponse.comnorthernresponse.com | Consumer Services | CA |
| 2025-01-28 | savoiesfoods.comsavoiesfoods.com | Agriculture and Food Production | US |
| 2025-01-23 | mgainnovation.commgainnovation.com | Technology | US |
| 2024-12-18 | cornwelltools.comcornwelltools.com | Consumer Services | US |
| 2025-01-24 | rashtiandrashti.comrashtiandrashti.com | Business Services | US |
| 2025-01-16 | alkodistributors.comalkodistributors.com | Consumer Services | US |
| 2025-01-14 | ttucorp.comttucorp.com | Technology | US |
| 2025-01-16 | jayaapparelgroup.comjayaapparelgroup.com | Consumer Services | US |

