Home/Threat Actor/Cactus
Threat Actor

Cactus

cactus_ransomware · ransomware_raas_independent_emergence · active since 2023-03

Cactus (canonical naming) is a Ransomware-as-a- Service (RaaS) operation emerging March 2023 with cluster-defining self-encrypting binary defense evasion tradecraft per Kroll May 2023 canonical disclosure ("Researchers at Kroll in a report in May set the ransomware operation apart due to the use of the encryption to protect the malware binary from being detected by security products"); independent RaaS attribution via Arctic Wolf Labs canonical November 2023 Qlik Sense exploitation disclosure ("Arctic Wolf labs is currently responding to several instances of Qlik Sense exploitation for initial access. Analysis is still ongoing, but based on research from Praetorian and gathered forensic evidence, we currently assess that based on patch level Qlik Sense is likely being exploited either via the combination or direct abuse of CVE-2023-41266, CVE-2023-41265 or potentially CVE-2023-48365 to achieve code execution") + Northwave April 2024 PrickSense whitepaper (122 Qlik Sense servers compromised) + Fox-IT disinformation tradecraft analysis + Cybersecurity Dive October 2024 Schneider Electric attribution + Darktrace + any.run + Bleeping Computer + Help Net Security + The Hacker News + ThreatDown industry coverage, with honest attribution caveat that country-of-origin attribution remains uncertain and no established lineage to prior RaaS groups (unlike Hunters International or Embargo successor profiles); standalone cluster paralleling hunters_international + embargo + trigona in v0.1.160 2022-2025 post- takedown + emerging RaaS cell.

operational target profile large enterprises primary scope per any.run + finance + manufacturing + IT + healthcare primary sectors + signature high-profile Schneider Electric January 2024 industrial-control- systems victim + signature global-supply-chain pivot victims Marfrig Global Foods + MINEMAN Systems with triple-extortion-via-partner-pivot tradecraft + 122 Qlik Sense servers compromised per Northwave with 3,143 vulnerable of 5,205 internet-facing instances scanned April 2024 per ThreatDown + U.S. primary geographic per Darktrace + Netherlands DIVD-tracking secondary.

operational attack architecture: (1) cluster-defining self- encrypting binary defense evasion tradecraft per Kroll May 2023 distinctive technique protecting malware binary from security-product detection.

(2) cluster-defining Qlik Sense 4-CVE zero-day exploitation chain with CVE-2023-41265 (CVSS 9.9 ZeroQlik HTTP Request Tunneling allowing privilege elevation + backend HTTP execution) + CVE-2023- 41266 (CVSS 6.5 path traversal generating anonymous sessions to unauthorized endpoints) + CVE-2023- 48365 (CVSS 9.9 DoubleQlik incomplete-patch-bypass unauthenticated RCE via improper HTTP header validation) per Praetorian discovery August- September 2023 + Arctic Wolf Labs November 2023 exploitation observation.

(3) signature Fortinet VPN appliance vulnerability exploitation prior 2023 campaign tradecraft per Bleeping Computer; (4) cluster-defining Qlik Sense Scheduler service + PowerShell + BITS (Background Intelligent Transfer Service) operational tradecraft with executables disguised as Qlik files + AnyDesk fetched from official sources for legitimate-tool masquerade.

(5) cluster-defining disinformation campaign tradecraft per Fox-IT analysis ("Cactus engaged in a disinformation campaign. The hackers at Cactus sowed false information about the breach to thwart mitigation efforts") distinctive post-breach signature setting Cactus apart from typical RaaS behavior.

(6) cluster-defining triple-extortion-via-partner-pivot signature tradecraft per any.run ("These attacks often involve pivoting from one compromised entity to its partners or clients, amplifying disruption. For instance, after breaching a primary target, Cactus operators have been known to use stolen credentials to access related networks, threatening to leak data from multiple entities unless ransoms are paid")

(7) signature AnyDesk remote-desktop + ManageEngine UEMS unified-endpoint-management + rclone cloud-exfiltration + MEGA cloud-storage + batch-scripts-uninstalling-security-products + PuTTY + Disk Analyzer legitimate-tools tradecraft per Bleeping Computer + Arctic Wolf + Cybersecurity Dive living-off-the-land operational pattern.

(8) signature RDP tunnel + password change reconnaissance lateral movement tradecraft per DashboardFox.

(9) signature different domain names per affiliates RaaS-affiliate-base operational framework per any.run.

(10) signature DIVD + NCSC + Digital Trust Center Netherlands public-private partnership coordinated victim notification operational response per Cybersecurity Dive + Fox-IT.

cluster fills the March-2023-emergence + self-encrypting-binary-defense-evasion + Qlik-Sense- zero-day-exploitation-4-CVE-chain + Fortinet-VPN- initial-access-prior + Schneider-Electric-January- 2024-victim + 122-Qlik-Sense-servers + disinformation- campaign-tradecraft + triple-extortion-via-partner- pivot + AnyDesk-ManageEngine-rclone-MEGA-legitimate- tools + Qlik-files-executable-disguise position in 2022-2025 post-takedown + emerging RaaS cell; canonical illustration of March 2023 emerging RaaS + self-encrypting binary defense evasion tradecraft + Qlik Sense 4-CVE-chain zero-day exploitation campaign + Fortinet VPN initial access + triple- extortion-via-partner-pivot signature + disinformation-campaign-tradecraft + AnyDesk + ManageEngine + rclone + MEGA legitimate-tools operational pattern + DIVD public-private partnership victim notification cited in essentially all subsequent emerging RaaS industry analyses through 2023-2026 period.

ransomware_raas_independent_emergence confidence: high 20 aliases

Profile

Cactus (canonical naming) is a Ransomware-as-a- Service (RaaS) operation emerging March 2023 with cluster-defining self-encrypting binary defense evasion tradecraft. Independent RaaS attribution via Arctic Wolf Labs canonical November 2023 Qlik Sense exploitation disclosure + Kroll May 2023 self-encrypting binary disclosure + Northwave April 2024 PrickSense whitepaper + Fox-IT disinformation tradecraft analysis + Cybersecurity Dive + Darktrace + any.run + Bleeping Computer + Help Net Security + The Hacker News industry coverage. Honest attribution caveat: country-of-origin attribution uncertain; no established lineage to prior RaaS groups.

Standalone cluster paralleling hunters_international + embargo + trigona in v0.1.160 2022-2025 post- takedown + emerging RaaS cell.

Operational target profile
  • Large enterprises primary scope.
  • Finance + manufacturing + IT + healthcare primary sectors.
  • Schneider Electric (January 2024), ICS victim.
  • Marfrig Global Foods + MINEMAN Systems, global supply chain pivot victims.
  • 122 Qlik Sense servers compromised per Northwave + 3,143 vulnerable of 5,205 scanned Operational attack architecture: (1) Self-encrypting binary defense evasion (cluster-defining): Kroll May 2023 signature distinctive tradecraft (2) Qlik Sense 4-CVE chain zero-day exploitation (cluster-defining): CVE-2023-41265 (ZeroQlik 9.9) + CVE-2023-41266 (path traversal 6.5) + CVE-2023-48365 (DoubleQlik bypass 9.9) (3) Fortinet VPN initial access (signature): prior 2023 campaign tradecraft (4) Disinformation campaign tradecraft (cluster- defining): per Fox-IT, sowing false breach information to thwart mitigation (5) Triple-extortion-via-partner-pivot (cluster- defining): per any.run, Marfrig + MINEMAN supply chain pivot signature (6) Qlik Sense Scheduler + PowerShell + BITS tradecraft (cluster-defining) (7) AnyDesk + ManageEngine UEMS + rclone + MEGA legitimate-tools tradecraft (signature) (8) Executables disguised as Qlik files (signature) (9) 122 Qlik Sense servers compromised (signature) The cluster fills the March-2023-emergence + self- encrypting-binary-defense-evasion + Qlik-Sense-zero- day-exploitation-4-CVE-chain-CVE-2023-41265-CVE- 2023-41266-CVE-2023-48365 + Fortinet-VPN-initial- access-prior + Schneider-Electric-January-2024 + 122-Qlik-Sense-servers + disinformation-campaign- tradecraft + triple-extortion-via-partner-pivot + AnyDesk-ManageEngine-rclone-MEGA-legitimate-tools position in 2022-2025 post-takedown + emerging RaaS cell.

Aliases

20
cactus_ransomwarecactuscactus ransomware-as-a-service raascactus march 2023 emergencecactus self-encrypting binary defense evasion signaturecactus qlik sense zero-day exploitation november 2023cactus cve-2023-41265 zeroqlik path traversal http tunnelingcactus cve-2023-41266 anonymous session unauthorized endpointcactus cve-2023-48365 doubleqlik bypass remote code executioncactus fortinet vpn initial access prior attackscactus arctic wolf labs canonical disclosurecactus schneider electric january 2024 attack victimcactus marfrig global foods mineman systems supply chain pivotcactus double extortion triple extortion via partner pivotcactus anydesk manage engine uems legitimate toolscactus rclone mega cloud exfiltrationcactus disinformation campaign tradecraft per fox-itcactus 122 qlik sense servers compromised northwavecactus 5205 instances 3143 vulnerable threatdowncactus storm-0062 darkshadow oro0lxy adjacent confluence campaign

Adversary Emulation Plan

4 steps
Runnable Caldera emulation profile Defense Evasion - General defense-evasion set of abilities. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 defense-evasion T1070.003 · Indicator Removal on Host: Clear Command History darwin, linux, windows
Avoid logs
> $HOME/.bash_history && unset HISTFILE
Disable Windows Defender All
Set-MpPreference -DisableIntrusionPreventionSystem $true;
Set-MpPreference -DisableIOAVProtection $true;
Set-MpPreference -DisableRealtimeMonitoring $true;
Set-MpPreference -DisableScriptScanning $true;
Set-MpPreference -EnableControlledFolderAccess Disabled;
4 defense-evasion T1059.001 · PowerShell windows
Move Powershell & triage
Copy-Item C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe C:\Windows\Temp\debug.exe;
C:\Windows\Temp\debug.exe get-process >> C:\Windows\temp\debug.log;
C:\Windows\Temp\debug.exe get-localgroup >> C:\Windows\temp\debug.log;
C:\Windows\Temp\debug.exe get-localuser >> C:\Windows\temp\debug.log;
C:\Windows\Temp\debug.exe Get-ItemProperty Registry::HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion >> C:\Windows\temp\debug.log;
Clear Logs
Clear-Eventlog Security;
Clear-Eventlog System;

Notable Campaigns

12
2024Cactus 122 Qlik Sense Servers Compromised, Northwave Analysis (2024)
2024Cactus 5,205 Qlik Sense Instances Scan, 3,143 Vulnerable (April 2024, ThreatDown)
2024Cactus Schneider Electric January 2024 Attack
2024Cactus Disinformation Campaign Tradecraft Signature (Fox-IT)
2024Cactus DIVD + NCSC + Digital Trust Center Netherlands Public-Private Partnership Victim Notification
2023-2026Continued Industry Reference Status (2023-2026)
2023-2024Cactus Marfrig Global Foods + MINEMAN Systems Supply Chain Pivot Signature
2023-2024Cactus Qlik Sense Scheduler + PowerShell + BITS Tradecraft Signature
2023-2024Cactus AnyDesk + ManageEngine UEMS + rclone + MEGA Legitimate Tools Tradecraft
2023Cactus Ransomware Origin, March 2023 Emergence
2023Cactus Self-Encrypting Binary Signature (Kroll May 2023)
2023Cactus Qlik Sense 4-CVE Chain Zero-Day Exploitation Campaign (November 2023)

Attribution & Reporting

Attributed by
Arctic Wolf Labs (canonical November 2023 Qlik Sense exploitation campaign disclosure + Stefan Hostetler December 2024 senior threat intelligence researcher)Praetorian (canonical Qlik Sense CVE-2023-41265 ZeroQlik + CVE-2023-41266 disclosure August 2023 + CVE-2023-48365 DoubleQlik bypass research September 2023)Kroll (canonical May 2023 self-encrypting binary defense evasion disclosure)Bleeping Computer (canonical Cactus ransomware exploiting Qlik Sense flaws November 30, 2023 coverage)Help Net Security (canonical December 1, 2023 Qlik Sense flaws exploited Cactus ransomware coverage)The Hacker News (canonical November 30, 2023 CACTUS Ransomware Exploits Qlik Sense Vulnerabilities coverage)Northwave (canonical PrickSense April 2024 How Cactus exploits Qlik Sense whitepaper + 122 Qlik Sense servers compromised + 2024 incident response)Fox-IT (canonical 2024 Cactus disinformation campaign tradecraft analysis)Cybersecurity Dive (canonical October 2024 Cactus ransomware Qlik Sense CVEs + Schneider Electric attribution)Darktrace (canonical April 2024 How Cactus Ransomware Was Detected and Stopped analysis)any.run (canonical Cactus malware trends tracker March 2025 comprehensive analysis)ThreatDown (canonical April 2024 + May 2024 Cactus exploits Qlik Sense + 5205 instances + 3143 vulnerable scan)DashboardFox (canonical September 2024 Qlik Sense Cactus Ransomware analysis)DIVD (Dutch Institute for Vulnerability Disclosure) (canonical public-private partnership victim notification)National Cyber Security Centrum + Digital Trust Center Netherlands (canonical victim notification public-private partnership)
Key reporting
reportArctic Wolf Labs: Qlik Sense Exploited in Cactus Ransomware Campaign (November 2023), canonical disclosure
reportKroll (May 2023): canonical self-encrypting binary defense evasion disclosure
reportPraetorian: canonical Qlik Sense CVE-2023-41265 ZeroQlik + CVE-2023-41266 disclosure August 2023 + CVE-2023-48365 DoubleQlik bypass research
reportNorthwave: PrickSense, How Cactus exploits Qlik Sense (April 2024), canonical 122 Qlik Sense servers + 2024 incident response
reportFox-IT: canonical 2024 Cactus disinformation campaign tradecraft analysis
reportCybersecurity Dive (October 2024): canonical Schneider Electric attribution
reportDarktrace (April 2024): canonical How Cactus Ransomware Was Detected and Stopped
reportBleeping Computer (November 30, 2023): canonical Cactus ransomware exploiting Qlik Sense flaws
reportHelp Net Security (December 1, 2023): canonical Qlik Sense flaws exploited Cactus ransomware
reportThe Hacker News (November 30, 2023): canonical CACTUS Ransomware Exploits Qlik Sense Vulnerabilities
reportany.run: canonical Cactus malware trends tracker
reportThreatDown (April 2024): canonical 5,205 instances + 3,143 vulnerable scan
reportDIVD + NCSC + Digital Trust Center Netherlands: canonical public-private partnership victim notification

Operational

State sponsor

Independent Ransomware-as-a-Service (RaaS) operation with no established lineage to prior RaaS groups (unlike Hunters International / Embargo successor profiles). RaaS affiliate-base model per any.run assessment based on different domain names used in attacks suggesting different affiliates perform attacks. Honest attribution caveat: country-of- origin attribution is uncertain, group operates with cybercrime-ecosystem-aligned tradecraft but explicit Russian-aligned linkage not established by primary sources.

Attribution chain: (1) Arctic Wolf Labs canonical November 2023 Qlik Sense exploitation campaign disclosure: per Arctic Wolf Labs: "Arctic Wolf labs is currently responding to several instances of Qlik Sense exploitation for initial access. Analysis is still ongoing, but based on research from Praetorian and gathered forensic evidence, we currently assess that based on patch level Qlik Sense is likely being exploited either via the combination or direct abuse of CVE-2023-41266, CVE-2023-41265 or potentially CVE-2023-48365 to achieve code execution." (2) Kroll May 2023 canonical self-encrypting binary disclosure: per Bleeping Computer: "Researchers at Kroll in a report in May set the ransomware operation apart due to the use of the encryption to protect the malware binary from being detected by security products. The researchers also highlighted the use of AnyDesk remote desktop application, the rclone tool to send stolen data to cloud storage services, and the use of batch scripts to uninstall security products." Cluster-defining self-encrypting tradecraft.

(3) Northwave + Fox-IT canonical 2024 campaign analysis: per Northwave: "The Cactus ransomware group moved quickly to exploit these vulnerabilities to gain access to what we assess is a substantial amount of 122 already exploited Qlik Sense servers. In January and April 2024, Northwave responded to two cases attacks where Cactus had used the exploits to deploy ransomware and extort its victims." (4) Cybersecurity Dive + Fox-IT canonical disinformation campaign tradecraft: per Cybersecurity Dive October 2024: "Cactus engaged in a disinformation campaign. The hackers at Cactus sowed false information about the breach to thwart mitigation efforts, according to Fox-IT researchers." (5) ThreatDown April 2024 canonical vulnerable- population scan: per ThreatDown: "Based on an initial scan on April 17, 2024, the researchers identified 5,205 Qlik Sense servers of which 3,143 seem to be vulnerable to the exploits used by the Cactus group." (6) any.run canonical comprehensive Cactus analysis: per any.run: "Cactus ransomware-as-a- service (RaaS) was first caught in March 2023 targeting corporate networks.

It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare... Cactus has been linked to attacks on companies like Marfrig Global Foods and MINEMAN Systems, both of which influence global supply chains.

These attacks often involve pivoting from one compromised entity to its partners or clients, amplifying disruption." (7) Cybersecurity Dive + Schneider Electric January 2024 attribution: per Cybersecurity Dive: "Cactus has been involved in some high profile threat activity in recent months. The group claimed credit for a ransomware attack in January against Schneider Electric." Operational mission objective: Financially-motivated RaaS double-extortion with cluster-defining triple-extortion-via-partner-pivot tradecraft. Cactus operators leverage initial- victim-compromised credentials to access related partner networks for cascading-extortion capability.

Operational target profile
  • Large enterprises primary scope per any.run + Bleeping Computer.
  • Finance + manufacturing + IT + healthcare primary sectors per any.run.
  • Schneider Electric (January 2024), high- profile industrial control system / ICS victim.
  • Marfrig Global Foods, global supply chain food victim.
  • MINEMAN Systems, global supply chain victim.
  • 122 Qlik Sense servers compromised per Northwave (with 3,143 vulnerable of 5,205 scanned April 2024 per ThreatDown)
  • U.S. primary geographic + global The cluster fills the March-2023-emergence + self- encrypting-binary-defense-evasion-signature + Qlik- Sense-zero-day-exploitation-4-CVE-chain-CVE-2023- 41265-CVE-2023-41266-CVE-2023-48365 + Fortinet-VPN- initial-access-prior + Schneider-Electric-January- 2024-victim + 122-Qlik-Sense-servers-compromised + disinformation-campaign-tradecraft + triple- extortion-via-partner-pivot + AnyDesk-ManageEngine- rclone-MEGA-legitimate-tools position in 2022-2025 post-takedown + emerging RaaS cell.
Motivations
financially_motivated_ransomware_as_a_service_double_triple_extortion, large_enterprise_targeting_primary_signature, self_encrypting_binary_defense_evasion_signature_capability, qlik_sense_zero_day_exploitation_signature_capability, disinformation_campaign_tradecraft_signature, triple_extortion_via_partner_pivot_signature_tradecraft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)35/60 · 58%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MANAGEENGINE UEMSMARFRIG GLOBAL FOODS + MINEMAN SYSTEMS SUPPLY CHAIN PIVOT VICTIMSMEGA CLOUD STORAGESCHNEIDER ELECTRIC JANUARY 2024 INDUSTRIAL VICTIM SIGNATURESELF-ENCRYPTING BINARY DEFENSE EVASION SIGNATURE DISTINCTIVE TRADECRAFT

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin