Cactus is a Windows ransomware family first identified in March 2023. Its operators conduct double-extortion attacks, stealing sensitive information before encrypting systems and threatening to publish the stolen data unless a ransom is paid. Cactus has targeted commercial organizations across multiple sectors worldwide, particularly in the United States and Europe, including manufacturing, construction, education, and critical infrastructure.
Documented intrusion campaigns exploit unpatched, internet-facing Qlik Sense installations through vulnerabilities including CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365. Other campaigns use email flooding followed by Microsoft Teams calls impersonating technical support to persuade victims to grant access through Microsoft Quick Assist. Operators also obtain access from initial access brokers; ToyMaker has handed compromised environments to Cactus. Post-compromise activity includes network and account discovery, credential theft, RDP-based lateral movement, SSH tunneling, and deployment of legitimate remote-management tools such as AnyDesk and ManageEngine UEMS. Operators use Rclone and other file-transfer utilities to exfiltrate data, remove security software, clear intrusion artifacts, and sometimes reboot systems into Safe Mode to weaken defenses. Compromised environments can remain inactive for weeks or months before ransomware deployment.
The encryptor uses OpenSSL-based AES-256-CBC file encryption and RSA protection of per-file encryption keys. It supports full encryption of smaller files and configurable partial encryption of larger files. Command-line options control setup, logging, encryption threads, encryption percentage, and selection of individual files or directories. Cactus can establish scheduled-task persistence, suppress its console window, and use a mutex to prevent concurrent execution. It uses Windows Restart Manager functionality to identify processes blocking target files, terminates selected processes and services, deletes Volume Shadow Copies, and disables backup services to hinder recovery. Encrypted files are renamed, and ransom notes are placed in processed directories.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The bypass for the incomplete mitigation is recorded under CVE-2023-48365 and is dubbed DoubleQlik. Whether the combination of CVE-2023-41266 and CVE-2023-41265, or CVE-2023-48365 is abused cannot be determined by analysing Qlik Sense logs.
Based on patch level Qlik Sense is likely being exploited either via the combination or direct abuse of CVE-2023-41266, CVE-2023-41265 or potentially CVE-2023-48365 to achieve code execution.
The vulnerability CVE-2023-41265 allowed the threat actor to elevate its privileges to a service account and execute these requests under the rights of this service account.
Initial entry point of Cactus ransomware is via exploiting VPN vulnerabilities (CVE-2023–38035). In this attack, the attacker measuredly targeted Fortinet VPN to exploit the VPN network and connect to internal networks.
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2024-40766: SonicWall SonicOS Improper Access Control (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In January and April 2024, Northwave responded to two separate incidents of organisations that were hit by the Cactus ransomware group. ... Both involved exploitation of the Qlik Sense vulnerabilities.”
ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."
TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.
Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Cactus ransomware creates a scheduled task to achieve persistence to execute itself from the%ProgramData% folder with '-r' argument.
Zodra toegang is verkregen, downloaden aanvallers aanvullende tools zoals AnyDesk en Plink en wijzigen ze het beheerderswachtwoord.
Cactus ransomware creates a scheduled task to achieve persistence to execute itself from the%ProgramData% folder with '-r' argument.
Ransomware is kwaadaardige software waarbij een slachtoffer afgeperst wordt, nadat zijn digitale systeem of de bestanden erop met een code op slot zijn gezet... Het gaat bij deze kwetsbaarheid om een specifieke vorm van ransomware die de naam 'Cactus' draagt.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion ransomware that encrypts files and threatens to leak stolen data if victims refuse payment. The article reports more than 100 targeted entities by April 2024. Its payload uses AES-256-CBC for file encryption and RSA-4096 to encrypt the AES keys, partially encrypts files larger than 7.7 MB, and appends .cts<numeric> extensions. It supports scheduled-task persistence, deletes shadow copies, disables backup services, terminates selected processes and services, and drops ransom notes in processed folders. The described attack chain includes VPN exploitation, credential theft, lateral movement, security-tool removal, and data exfiltration before encryption.
Named ransomware family used by former BlackBasta affiliates after BlackBasta disbanded.
A ransomware operation described as collaborating with Black Basta. The chats suggest payments between the groups and operational familiarity.
Associated Analytic Story Insider Threat Command And Control Ransomware Cactus Ransomware
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.