Cactus — Ransomware Profile
Cactus ransomware is notable for encrypting its own binary to evade detection, exploiting VPN vulnerabilities for initial access.Also tracked as
CACTUS
Tools & malware
- AnyDesk Remote management tool
- Cactus Ransomware/Encryptor
- Chisel Tunneling/proxy tool
- Cobalt Strike Post-exploitation framework
- DanaBot Loader/initial-access malware
- Rclone Data exfiltration tool
- SoftPerfect Network Scanner Network discovery tool
- Splashtop Remote management tool
- SuperOps Remote management tool (RMM)
- TotalExec PowerShell deployment script
Recent claimed victims
- optiline.com 2025-03-21
- fplfood.com 2025-03-21
- biagibros.com 2025-03-21
- kyb.com 2025-03-17
- assaabloy.com 2025-03-17
- urban1.com 2025-03-12
- thermoid.com 2025-03-12
- tempel.com 2025-03-12
- rocketstores.com 2025-03-12
- baillie.com 2025-03-12
- quigleyeye.com 2025-03-03
- stanleyconsultants.com 2025-02-28
- alphabaking.com 2025-02-26
- holtcat.com 2025-02-26
- caltrol.com 2025-02-26
- lifting.com 2025-02-25
- bluedge.com 2025-02-25
- regulvar.com 2025-02-24
- branchgroup.com 2025-02-24
- everelgroup.com 2025-02-24
- associatedasset.com 2025-02-24
- chfindustries.com 2025-02-24
- grede.com 2025-02-24
- pace-usa.com 2025-02-24
- steelwarehouse.com 2025-02-24
Vendor research
- Cactus Ransomware: Prickly New Variant Evades Detection Kroll
- New Cactus ransomware encrypts itself to evade antivirus BleepingComputer
- CACTUS: Analyzing a Coordinated Ransomware Attack on Corporate Networks Bitdefender
- Cactus ransomware exploiting Qlik Sense flaws to breach networks BleepingComputer
- Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware The Hacker News