Inactive ransomware operator
← All groupsCactus
552 victims indexed · first seen 3 years ago · last activity 1 year ago
At a glance
- Status
- inactive
- First seen
- 3 years ago
- Last activity
- 1 year ago
- Onion sites
- 2 known endpoints
- Primary sector
- Manufacturing · 34 hits
About
References
10 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/cactus
- kroll.com/en/insights/publications/cyber/cactus-ransomware-prickly-new-variant-evades-detection
- socradar.io/dark-web-profile-cactus-ransomware/
- securityscorecard.com/wp-content/uploads/2024/01/Whitepaper-Cactus-Ransomware.pdf
- thehackernews.com/2023/11/cactus-ransomware-exploits-qlik-sense.html
- sentinelone.com/anthology/cactus-ransomware/
- blog.barracuda.com/2024/03/20/who-is-behind-cactus-ransomware
- kroll.com/en/publications/cyber/cactus-ransomware-prickly-new-variant-evades-detection
- tripwire.com/state-of-security/cactus-ransomware-what-you-need-know
- trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html
Timeline
20 monthsTop countries
Top sectors
MITRE ATT&CK
15 techniques · 10 tacticsTactics
Techniques
- T1003OS Credential Dumping
- T1056.001Keylogging
- T1059.001PowerShell
- T1059.006Python
- T1068Exploitation for Privilege Escalation
- T1069.001Local Groups
- T1090.002External Proxy
- T1105Ingress Tool Transfer
- T1135Network Share Discovery
- T1203Exploitation for Client Execution
- T1204.002Malicious File
- T1210Exploitation of Remote Services
- T1505.003Web Shell
- T1566.001Spearphishing Attachment
- T1574.001DLL
Recent victims
Loading…
Onion infrastructure
2 known- http://cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion
- https://cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
