Cactus is a Windows ransomware family and ransomware-as-a-service operation first identified in March 2023. It encrypts victim data using per-file AES encryption protected by an embedded RSA public key, supports configurable encryption scope and threading, and can partially encrypt large files to accelerate impact. Encrypted files receive Cactus-specific extensions and the malware deploys a ransom note.
Cactus supports persistence through scheduled tasks, enumerates local and attached drives, avoids selected operating-system and application directories, and uses Restart Manager functionality to identify processes locking target files. Operators have also been observed deleting evidence, deploying remote-administration tools, creating unauthorized accounts, establishing reverse-shell access, performing endpoint and network reconnaissance, moving laterally, archiving data, and exfiltrating victim data before encryption. The operation is associated with double extortion.
Observed intrusions have exploited unpatched internet-exposed Qlik Sense Enterprise servers, including CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365. Other Cactus-linked campaigns used spam flooding, Microsoft Teams voice phishing, and social engineering to persuade targets to grant access through Microsoft Quick Assist. Cactus activity has affected critical infrastructure, manufacturing, construction, and Dutch organizations among other sectors. Reporting identifies operational and tradecraft overlap with Black Basta, including apparent migration of some former Black Basta affiliates to Cactus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Het NCSC ontvangt rapporten dat de kwetsbaarheden actief worden misbruikt op Nederlandse systemen. Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten. | Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten, welke grote schade aanricht.
Het NCSC ontvangt rapporten dat de kwetsbaarheden actief worden misbruikt op Nederlandse systemen. Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten. | Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten, welke grote schade aanricht.
Het NCSC ontvangt rapporten dat de kwetsbaarheden actief worden misbruikt op Nederlandse systemen. Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten. | Kwaadwillenden gebruiken de kwetsbaarheden om Cactus ransomware in te zetten, welke grote schade aanricht.
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2024-40766: SonicWall SonicOS Improper Access Control (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.
Since November 2023, the Cactus ransomware group has been actively targeting vulnerable Qlik Sense servers.
Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
After a few days, the actors call the victim, usually via Microsoft Teams, and direct them to initiate a Microsoft Quick Assist remote access session...
De kwetsbaarheden in Qlik Sense Enterprise stellen ongeauthenticeerde kwaadwillenden in staat om het systeem waar Qlik Sense op is geïnstalleerd, over te nemen. CVE-2023-41265, CVE-2023-41266 en CVE-2023-48365 worden direct of in combinatie misbruikt om systemen met ransomware te besmetten.
Zodra toegang is verkregen, downloaden aanvallers aanvullende tools zoals AnyDesk en Plink en wijzigen ze het beheerderswachtwoord.
Ransomware is kwaadaardige software waarbij een slachtoffer afgeperst wordt, nadat zijn digitale systeem of de bestanden erop met een code op slot zijn gezet... Het gaat bij deze kwetsbaarheid om een specifieke vorm van ransomware die de naam 'Cactus' draagt.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family used by former BlackBasta affiliates after BlackBasta disbanded.
A ransomware operation described as collaborating with Black Basta. The chats suggest payments between the groups and operational familiarity.
Associated Analytic Story Insider Threat Command And Control Ransomware Cactus Ransomware
A ransomware family mentioned as one of the operations used by former BlackBasta affiliates after BlackBasta’s shutdown.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.