Cactus is a ransomware family and ransomware-as-a-service operation active since at least 2023 and used in financially motivated intrusions worldwide. It has been associated with double-extortion activity in which operators steal data before encrypting systems and then pressure victims through leak-site publication. Reporting links Cactus to intrusions against multiple sectors, including manufacturing, construction, critical infrastructure, and organizations exposed through vulnerable internet-facing services.
Cactus has been observed in campaigns using several initial access paths. Confirmed intrusion vectors include exploitation of vulnerable Qlik Sense servers and social-engineering-driven access chains involving spam flooding, Microsoft Teams impersonation, and Quick Assist remote sessions. In some incidents, access was handed off from an initial access broker to Cactus operators, who then used stolen credentials to expand through the environment.
Post-compromise activity attributed to Cactus includes endpoint and server enumeration, file discovery, deployment of remote administration tools, scheduled-task-based persistence, creation of unauthorized accounts, use of OpenSSH reverse shells, data archiving and exfiltration, and preparation for ransomware deployment. Operators have also been observed deleting artifacts, removing accounts used earlier in the intrusion, rebooting hosts into Safe Mode, and deleting shadow copies or otherwise inhibiting recovery prior to encryption. A newer variant has been reported with expanded command-line options that give operators finer control over execution.
Cactus has notable ecosystem overlap with other ransomware operations. Multiple assessments indicate tradecraft and personnel links with Black Basta, including shared use of BackConnect malware and similar social-engineering patterns. Some reporting also notes shared affiliates or victim overlap with other major ransomware brands. Cactus should therefore be understood both as a distinct ransomware family and as part of a fluid affiliate ecosystem in which operators, access brokers, and tooling can shift between banners.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For those looking for in-depth coverage of these exploits, the Arctic Wolf blog provides detailed insights into the specific vulnerabilities being exploited, notably CVE-2023-41266, CVE-2023-41265 also known as ZeroQlik, and potentially CVE-2023-48365 also known as DoubleQlik.
For those looking for in-depth coverage of these exploits, the Arctic Wolf blog provides detailed insights into the specific vulnerabilities being exploited, notably CVE-2023-41266, CVE-2023-41265 also known as ZeroQlik, and potentially CVE-2023-48365 also known as DoubleQlik.
Retrieving this file with the ?.ttf extension trick has been fixed in the patch that addresses CVE-2023-48365... Nevertheless, this is still a good way to determine the state of a Qlik instance, because if it redirects using 302 Authenticate at this location it is likely that the server is not vulnerable to CVE-2023-48365.
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2024-40766: SonicWall SonicOS Improper Access Control (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
TrendMicro analyzed the BlackBasta and Cactus groups as being the work of the same attack group in that they used the same BackConnect malware in an attack strategy that used social engineering techniques to gain initial access and then exploited Microsoft Teams and Quick Assist.
Since November 2023, the Cactus ransomware group has been actively targeting vulnerable Qlik Sense servers.
Following BlackBasta’s shutdown, its former affiliates did not simply disappear. Instead, they regrouped and continued their criminal activities under different ransomware families, including Cactus, and more recently, Payouts King.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The Black Basta group discovered that they had not encrypted the Ascension Healthcare data correctly due to a crypt error and decided to share the decryption key to avoid potential political sanctions and retaliation from US law enforcement against their infrastructure.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family used by former BlackBasta affiliates after BlackBasta disbanded.
A ransomware operation described as collaborating with Black Basta. The chats suggest payments between the groups and operational familiarity.
Associated Analytic Story Insider Threat Command And Control Ransomware Cactus Ransomware
A ransomware family mentioned as one of the operations used by former BlackBasta affiliates after BlackBasta’s shutdown.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.