cactus

Ransomware
Fuenteransomware.live

Sobre el grupo

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs

Vulnerabilidades explotadas

Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.

Impacto y víctimas

El grupo cactus tiene 1 víctimas de ransomware conocidas. Ve los sectores y países más afectados y las víctimas recientes.

1víctimas conocidas
1en Brasil
1sectores afectados
Sectores más atacados
Agriculture and Food Production1
Países más afectados
🇧🇷 Brasil1
Víctimas recientes
Marfrig Global FoodsAgriculture and Food Production · BR · 2023-09-05

El grupo cactus usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →