cactus logo

cactus

2 incidentes 1 paises 0 sectores ransomware MY Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Cactus is a ransomware-as-a-service (RaaS) operation that emerged in March 2023, primarily motivated by financial gain through a double extortion model. The group distinguishes itself by encrypting its own binary to evade detection, which it only unpacks when executed. While its exact origin remains unknown, some researchers speculate connections to Russia or a Malaysian hacktivist group. Cactus operators have demonstrated an evolving operational model, with evidence in January 2025 suggesting a potential transition or close affiliation of members from the Black Basta ransomware group, indicating a shared use of tactics, techniques, and procedures.
Malware asociado
NerbianRAT
Tecnicas MITRE
T1059, T1068, T1033, T1490, T1573, T1565
CVEs relacionadas
CVE-2024-21893, CVE-2024-21888, CVE-2024-21887, CVE-2023-48365, CVE-2023-46805, CVE-2023-43177

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

ArgentinaAustraliaBelgiumBrazilBahamasCanadaSwitzerlandChileCyprusGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: cactus (6 notes from ThreatLabz)18 Jun 2026
Report United States
cactus - Ransom NotesEste grupo de ransomware tiene 6 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de rescat…