Cactus
Cactus (canonical naming) is a Ransomware-as-a- Service (RaaS) operation emerging March 2023 with cluster-defining self-encrypting binary defense evasion tradecraft per Kroll May 2023 canonical disclosure ("Researchers at Kroll in a report in May set the ransomware operation apart due to the use of the encryption to protect the malware binary from being detected by security products"); independent RaaS attribution via Arctic Wolf Labs canonical November 2023 Qlik Sense exploitation disclosure ("Arctic Wolf labs is currently responding to several instances of Qlik Sense exploitation for initial access. Analysis is still ongoing, but based on research from Praetorian and gathered forensic evidence, we currently assess that based on patch level Qlik Sense is likely being exploited either via the combination or direct abuse of CVE-2023-41266, CVE-2023-41265 or potentially CVE-2023-48365 to achieve code execution") + Northwave April 2024 PrickSense whitepaper (122 Qlik Sense servers compromised) + Fox-IT disinformation tradecraft analysis + Cybersecurity Dive October 2024 Schneider Electric attribution + Darktrace + any.run + Bleeping Computer + Help Net Security + The Hacker News + ThreatDown industry coverage, with honest attribution caveat that country-of-origin attribution remains uncertain and no established lineage to prior RaaS groups (unlike Hunters International or Embargo successor profiles); standalone cluster paralleling hunters_international + embargo + trigona in v0.1.160 2022-2025 post- takedown + emerging RaaS cell.
operational target profile large enterprises primary scope per any.run + finance + manufacturing + IT + healthcare primary sectors + signature high-profile Schneider Electric January 2024 industrial-control- systems victim + signature global-supply-chain pivot victims Marfrig Global Foods + MINEMAN Systems with triple-extortion-via-partner-pivot tradecraft + 122 Qlik Sense servers compromised per Northwave with 3,143 vulnerable of 5,205 internet-facing instances scanned April 2024 per ThreatDown + U.S. primary geographic per Darktrace + Netherlands DIVD-tracking secondary.
operational attack architecture: (1) cluster-defining self- encrypting binary defense evasion tradecraft per Kroll May 2023 distinctive technique protecting malware binary from security-product detection.
(2) cluster-defining Qlik Sense 4-CVE zero-day exploitation chain with CVE-2023-41265 (CVSS 9.9 ZeroQlik HTTP Request Tunneling allowing privilege elevation + backend HTTP execution) + CVE-2023- 41266 (CVSS 6.5 path traversal generating anonymous sessions to unauthorized endpoints) + CVE-2023- 48365 (CVSS 9.9 DoubleQlik incomplete-patch-bypass unauthenticated RCE via improper HTTP header validation) per Praetorian discovery August- September 2023 + Arctic Wolf Labs November 2023 exploitation observation.
(3) signature Fortinet VPN appliance vulnerability exploitation prior 2023 campaign tradecraft per Bleeping Computer; (4) cluster-defining Qlik Sense Scheduler service + PowerShell + BITS (Background Intelligent Transfer Service) operational tradecraft with executables disguised as Qlik files + AnyDesk fetched from official sources for legitimate-tool masquerade.
(5) cluster-defining disinformation campaign tradecraft per Fox-IT analysis ("Cactus engaged in a disinformation campaign. The hackers at Cactus sowed false information about the breach to thwart mitigation efforts") distinctive post-breach signature setting Cactus apart from typical RaaS behavior.
(6) cluster-defining triple-extortion-via-partner-pivot signature tradecraft per any.run ("These attacks often involve pivoting from one compromised entity to its partners or clients, amplifying disruption. For instance, after breaching a primary target, Cactus operators have been known to use stolen credentials to access related networks, threatening to leak data from multiple entities unless ransoms are paid")
(7) signature AnyDesk remote-desktop + ManageEngine UEMS unified-endpoint-management + rclone cloud-exfiltration + MEGA cloud-storage + batch-scripts-uninstalling-security-products + PuTTY + Disk Analyzer legitimate-tools tradecraft per Bleeping Computer + Arctic Wolf + Cybersecurity Dive living-off-the-land operational pattern.
(8) signature RDP tunnel + password change reconnaissance lateral movement tradecraft per DashboardFox.
(9) signature different domain names per affiliates RaaS-affiliate-base operational framework per any.run.
(10) signature DIVD + NCSC + Digital Trust Center Netherlands public-private partnership coordinated victim notification operational response per Cybersecurity Dive + Fox-IT.
cluster fills the March-2023-emergence + self-encrypting-binary-defense-evasion + Qlik-Sense- zero-day-exploitation-4-CVE-chain + Fortinet-VPN- initial-access-prior + Schneider-Electric-January- 2024-victim + 122-Qlik-Sense-servers + disinformation- campaign-tradecraft + triple-extortion-via-partner- pivot + AnyDesk-ManageEngine-rclone-MEGA-legitimate- tools + Qlik-files-executable-disguise position in 2022-2025 post-takedown + emerging RaaS cell; canonical illustration of March 2023 emerging RaaS + self-encrypting binary defense evasion tradecraft + Qlik Sense 4-CVE-chain zero-day exploitation campaign + Fortinet VPN initial access + triple- extortion-via-partner-pivot signature + disinformation-campaign-tradecraft + AnyDesk + ManageEngine + rclone + MEGA legitimate-tools operational pattern + DIVD public-private partnership victim notification cited in essentially all subsequent emerging RaaS industry analyses through 2023-2026 period.