Aller au contenu principal
Retour à la base de rançongiciels
Groupe de rançongiciel

cactus

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs

Victimes connues248

Niveau de menace

ÉLEVÉ

Tactiques, techniques et procédures (TTP)

DiscoveryEnum

  • Nmap
  • SoftPerfect NetScan

Exfiltration

  • RClone

Networking

  • Chisel

Offsec

  • Cobalt Strike

RMM-Tools

  • AnyDesk
  • Splashtop
  • SuperOps
0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de cactus.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs