cactus
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs
Niveau de menace
ÉLEVÉ
Tactiques, techniques et procédures (TTP)
DiscoveryEnum
- Nmap
- SoftPerfect NetScan
Exfiltration
- RClone
Networking
- Chisel
Offsec
- Cobalt Strike
RMM-Tools
- AnyDesk
- Splashtop
- SuperOps
Vérifier si vous êtes touché
Cherchez dans notre base si votre organisation figure sur la liste des victimes de cactus.
score de risque · catégories de menace · sources · ancienneté · confiance — en une requête