Cactus
Cactus ransomware surfaced in March 2023 and has quickly become one of the fastest-growing and most aggressive ransomware-as-a-service (RaaS) variants. It follows a double-extortion model, encrypting files and threatening to leak stolen data to pressure victims. Cactus is notable for its ability to encrypt its own executable, evading detection by anti-malware tools, and for exploiting vulnerabilities in VPN appliances (e.g., Qlik Sense, Fortinet VPN) to gain initial access. Targets span global enterprises—including Schneider Electric and the Housing Authority of Los Angeles—and the group appears highly adaptable, often deploying the BackConnect persistence tool commonly associated with Black Basta. The ransomware changes file extensions to variants like .cts0 or .cts1, and places a ransom note named cAcTuS.readme.txt.
Países más afectados
Sin datos todavía.
Sectores más afectados
Sin datos todavía.
Víctimas recientes
Sin datos todavía.
Las reivindicaciones las publican los propios grupos criminales y no están verificadas hasta que la organización o la prensa las confirman. Los nombres de personas físicas (autónomos, profesionales individuales) se anonimizan conforme al RGPD. Nunca enlazamos a sitios de filtración ni a datos robados. Para solicitar la retirada o anonimización de una entrada, contacte con el administrador del sitio.
Fuentes: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.