Description Summary
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.
Threat Actor
RaaS, double extortion; initial access via Qlik Sense CVEs (ZeroQlik/DoubleQlik) and Fortinet VPN; LotL (PowerShell, Rclone, RMM).
Technical Indicators
Encryption Extension
.CTS1
Encryption Algorithm
Not publicly reported
Ransom Note Name
cAcTuS.readme.txt
Targeted Industries
Cross-sector (per leak-site victim telemetry)
First Seen
March 2023
Last Seen
Active
Geographical Location
Global / not publicly profiled
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |