Cactus is a ransomware family and ransomware operation active worldwide since at least March 2023, with reporting also describing it as linked to multiple attacks worldwide since late 2023. It is used in double-extortion campaigns in which operators steal data and encrypt victim systems, and victims are pressured through leak-site publication. Reported behavior includes deleting shadow copies before encryption to inhibit recovery and using the Windows Restart Manager library (RstrtMgr.dll) to kill processes that would otherwise lock files and interfere with encryption.
High-confidence reporting links Cactus to financially motivated ransomware activity and to shared or migrating affiliates from other major ransomware ecosystems. Multiple sources note overlap with Black Basta, including use of BackConnect malware previously seen in Black Basta attacks, similar TTPs such as email flooding followed by Microsoft Teams or Quick Assist social engineering, and assessments that some former Black Basta members or affiliates moved to Cactus. Cisco Talos also reported a 2023 intrusion in which an initial access broker it tracks as ToyMaker exploited vulnerable internet-facing systems, deployed the LAGTOY backdoor, harvested credentials from memory, and later handed access to Cactus.
Observed Cactus intrusion activity includes use of stolen credentials; endpoint, server, and file enumeration; archiving data with 7z; exfiltration with curl and other transfer tools; deletion of command history and Terminal Server Client artifacts; deployment of remote administration tools including eHorus Agent, AnyDesk, RMS Remote Admin, and OpenSSH; creation of scheduled tasks for recurring OpenSSH reverse shells over port 443; creation of unauthorized accounts such as "whiteninja"; modification of Winlogon registry keys; and use of bcdedit and shutdown commands to reboot hosts into Safe Mode, likely to weaken or evade security products. Talos also observed Metasploit shellcode-injected copies of PuTTY and ApacheBench, plus ELF binaries, communicating with 51.81.42.234 over ports 53, 443, 8343, and 9232.
Cactus has been associated with campaigns targeting manufacturing and construction organizations, and Talos reported a major pre-ransomware/ransomware campaign using Black Basta and later Cactus tradecraft in which actors spammed victims’ inboxes, contacted them via Microsoft Teams, convinced them to launch Quick Assist sessions, established persistence, and then conducted privilege escalation and lateral movement. Talos identified a previously undocumented Cactus ransomware variant with new command-line arguments that gave operators greater control over the binary. Cactus has also been tied to attacks against organizations with exposed or outdated Qlik Sense servers. Joint research under Project Melissa found that identified Dutch victims were compromised through internet-exposed Qlik Sense servers not running the latest version; the project estimated about 5,200 Qlik Sense servers were internet reachable worldwide, more than 3,100 were vulnerable, and 122 had likely already been exploited by Cactus.
Known indicators and notable artifacts directly mentioned in the content include the attacker-created local administrator account "support" with password "Sup0rtadmin" during the ToyMaker phase preceding Cactus access; unauthorized account "whiteninja"; the LAGTOY/HOLERUN backdoor persisted as service "WmiPrvSV"; modification of permissions on C:\Windows\Temp\syslog.txt to protect an SSH private key; and network communications to 51.81.42.234 on ports 53, 443, 8343, and 9232. Reporting also notes Dutch victimization, worldwide distribution, and later ecosystem reporting that listed Cactus among groups that became dormant or ceased operations in 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For those looking for in-depth coverage of these exploits, the Arctic Wolf blog provides detailed insights into the specific vulnerabilities being exploited, notably CVE-2023-41266, CVE-2023-41265 also known as ZeroQlik, and potentially CVE-2023-48365 also known as DoubleQlik.
For those looking for in-depth coverage of these exploits, the Arctic Wolf blog provides detailed insights into the specific vulnerabilities being exploited, notably CVE-2023-41266, CVE-2023-41265 also known as ZeroQlik, and potentially CVE-2023-48365 also known as DoubleQlik.
Retrieving this file with the ?.ttf extension trick has been fixed in the patch that addresses CVE-2023-48365... Nevertheless, this is still a good way to determine the state of a Qlik instance, because if it redirects using 302 Authenticate at this location it is likely that the server is not vulnerable to CVE-2023-48365.
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2024-40766: SonicWall SonicOS Improper Access Control (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.
Since November 2023, the Cactus ransomware group has been actively targeting vulnerable Qlik Sense servers.
Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The Black Basta group discovered that they had not encrypted the Ascension Healthcare data correctly due to a crypt error and decided to share the decryption key to avoid potential political sanctions and retaliation from US law enforcement against their infrastructure.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family used by former BlackBasta affiliates after BlackBasta disbanded.
A ransomware operation described as collaborating with Black Basta. The chats suggest payments between the groups and operational familiarity.
A ransomware family mentioned as one of the operations used by former BlackBasta affiliates after BlackBasta’s shutdown.
Ransomware family referenced as having intrusions that used similar email-bombing + Teams impersonation + Quick Assist tradecraft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.