Ransomware Group: cactus

Fecha
25 Jun 2026
Actor
cactus
Tipo
Threat-actor
Pais
United States
Sector
-
Confianza
high
60
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

2IOCs
0TTPs
cactusActor
United StatesPais
Executive Summary
Perfil del grupo segun ransomware.anggipradana.com.

Key Points

  • Ransomware Dashboard

Grupo Ransomware: cactus

Perfil del grupo segun ransomware.anggipradana.com.

CampoValor
Alias
Pais
Estado

Descripcion

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs

Referencias

Diamond Model

Adversary
cactus
Ver perfil →
Victim
Ransomware Group: cactus
United States
Capability
Threat-actor
Infrastructure
github.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File cAcTuS.readme.txt Artefacto observado VT OffSec SOCRadar
Domain github.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor cactus en el blog → Ver cactus en IntelTracker → URL IntelTracker: ransomware.anggipradana.com → Fuente OSINT: ransomware.anggipradana.com → Buscar cactus en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes