Threat actors have actively exploited internet-exposed Qlik Sense Enterprise for Windows servers using the critical vulnerabilities CVE-2023-41265, CVE-2023-41266, and potentially CVE-2023-48365 to obtain unauthenticated code execution and deploy Cactus ransomware. The activity affected organizations including several Dutch companies that had not applied security updates; Dutch authorities raised the threat assessment to High/High and urged immediate patching of exposed servers.
Following access, processes launched by the Qlik Sense Scheduler service (Scheduler.exe) executed PowerShell and command-shell activity to download remote-access and persistence tools, including renamed ManageEngine UEMS components, AnyDesk, and PuTTY/Plink. Operators disabled Sophos, changed local administrator passwords, established Plink RDP tunnels over port 443, moved laterally through RDP, and staged data with rclone—renamed svchost.exe—before deploying ransomware. Qlik issued security patches for the affected Qlik Sense Enterprise for Windows flaws in August and September 2023.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
A Dutch supplier of schoolbooks and digital educational materials was affected by Cactus ransomware earlier in the month referenced by the NCSC advisory.
The Dutch NCSC reported active ransomware-group exploitation of unpatched internet-connected Qlik Sense Enterprise servers, including against Dutch companies. The Digital Trust Center notified organizations with exposed servers, and the NCSC raised the vulnerabilities' threat rating to High/High.
During observed Qlik Sense compromises, attackers used Scheduler.exe to launch commands that installed or downloaded ManageEngine UEMS components, AnyDesk, and Plink; they also changed administrator passwords, used RDP for lateral movement, and in at least one case used renamed rclone for data exfiltration before ransomware deployment.
Arctic Wolf Labs observed a campaign in which a threat actor exploited publicly exposed Qlik Sense installations, using CVE-2023-41265 and CVE-2023-41266 and possibly CVE-2023-48365 for code execution and eventual Cactus ransomware deployment.
Qlik published an advisory covering critical security fixes for Qlik Sense Enterprise for Windows.
Qlik announced that new security patches were available for Qlik Sense Enterprise for Windows.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcearcticwolf.com
Open sourcecommunity.qlik.com
Open sourcecommunity.qlik.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.