Dutch public-private partnership Project Melissa identified multiple Dutch organizations compromised by the Cactus ransomware group after attackers exploited internet-exposed, unpatched Qlik Sense Enterprise servers. The campaign, observed globally from late 2023 through March 2024, abused CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365, which can enable unauthenticated takeover of affected Qlik Sense hosts. QlikTech had released updates for supported versions, but affected victims had not applied the latest patches.
Attackers installed AnyDesk and Plink, changed administrator passwords, used RDP for lateral movement, and deployed ransomware. Project Melissa partners Fox-IT, Northwave, Responders, and ESET Nederland shared indicators in April and used internet scanning to identify exposed systems: roughly 5,200 Qlik Sense servers were internet-reachable worldwide, more than 3,100 were vulnerable, and 122 showed likely Cactus exploitation. The Dutch NCSC rated the threat High/High, while the Digital Trust Center, NCSC, DIVD, police, and international CSIRTs coordinated notifications; organizations should immediately patch exposed Qlik Sense servers and investigate for the published indicators of compromise.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
The Cactus ransomware group began carrying out multiple attacks worldwide, including attacks that exploited unpatched Qlik Sense servers for initial access.
The Dutch public-private Project Melissa collaboration began, bringing together government, law-enforcement, and cybersecurity-industry participants to combat ransomware.
The Dutch NCSC raised the threat assessment for the exploited Qlik Sense vulnerabilities to High/High, indicating a high likelihood of exploitation and potentially severe impact.
Authorities reported active exploitation of CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365 against internet-connected Qlik Sense Enterprise servers, including at Dutch companies that had not updated their systems. Attackers used tools including AnyDesk and Plink, changed administrator passwords, and used RDP for lateral movement and ransomware deployment.
QlikTech released updates for supported Qlik Sense versions, and the Dutch NCSC issued security guidance concerning the vulnerabilities exploited by Cactus.
Fox-IT fingerprinted and scanned for vulnerable or likely abused Qlik Sense servers, and the results were provided to DIVD, the NCSC, and the DTC. The DTC notified Dutch organizations, while DIVD and police shared affected-server information with foreign CSIRTs and law-enforcement services.
Fox-IT, Northwave, and Responders shared technical indicators of compromise related to Cactus to help prevent further attacks. Joint analysis with ESET Nederland found victims had been accessed through outdated Qlik Sense servers.
Monthly Project Melissa ransomware statistics showed that at least ten Dutch organizations had become Cactus victims through March 2024.
Project Melissa was formally codified through a covenant defining legal, organizational, and technical arrangements for the partnership.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcecyberveilignederland.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.