CA

Cactus Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Mar 21, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Manufacturing
157
Total Victims
0.7% of all tracked
20
Countries Targeted
13
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Cactus and from this database. Figures and technique mappings are quoted from the source data, not inferred.

The Cactus ransomware emerged in March 2023 and has infected a reported 157 victims across 20 countries, targeting sectors like manufacturing, business services, and technology.

Who Cactus is

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox. Source: https://github.com/crocodyli/ThreatActors-TTPs

Recorded activity

Disclosures attributed to Cactus in this database run from January 2024 to March 2025, totalling 157 victims — 0.7% of everything tracked here. Cactus has listed victims in 20 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Manufacturing, Business Services, Technology.

How Cactus is documented to operate

Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Software Deployment Tools T1072 Execution Lateral Movement

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems.

Mitigations: Remote Data Storage, Limit Software Installation, User Training, Network Segmentation, Password Policies, User Account Management

MITRE ATT&CK reference →
Create Account T1136 Persistence

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system. Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.

Mitigations: Operating System Configuration, Network Segmentation, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
Obfuscated Files or Information T1027 Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit

MITRE ATT&CK reference →
Disable or Modify Tools T1685 Defense Impairment

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Mitigations: Execution Prevention, User Account Management, Restrict File and Directory Permissions, Restrict Registry Permissions, Software Configuration, Audit

MITRE ATT&CK reference →
OS Credential Dumping T1003 Credential Access

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

Mitigations: Encrypt Sensitive Information, Behavior Prevention on Endpoint, Password Policies, User Training, Privileged Account Management, Privileged Process Integrity

MITRE ATT&CK reference →
Credentials from Web Browsers T1555.003 Credential Access

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <codeAppData\Local\Google\Chrome\User Data\Default\Login Data</code and executing a SQL query: <codeSELECT actionurl, usernamevalue, passwordvalue FROM logins;</code.

Mitigations: Restrict Web-Based Content, User Training, Password Policies, User Account Management, Update Software

MITRE ATT&CK reference →
Remote System Discovery T1018 Discovery

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <codenet view</code using Net, or, on ESXi servers, esxcli network diag ping. Adversaries may also analyze data from local host files (ex: <codeC:\Windows\System32\Drivers\etc\hosts</code or <code/etc/hosts</code) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Cactus across its recorded activity. They describe the group overall, not any single incident.

Tooling observed in Cactus operations

  • Nmap
  • SoftPerfect NetScan
  • RClone
  • Chisel
  • Cobalt Strike
  • AnyDesk
  • Splashtop
  • SuperOps

Software reported in use by Cactus. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

Showing a sample of 50 MD5, 3 EMAIL on file. Hashes and network indicators published for Cactus. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

cactus.yar
rule CactusRule 
{ 
    strings: 
        $cactusStr = “CaCtUs.ReAdMe.txt” 
        $cactusHex = { 43 61 43 74 55 73 2e 52 65 41 64 4d 65 2e 74 78 74 } 
    condition: 
        $cactusStr or $cactusHex 
} 

rule CactusRansomware {
	meta:
		description = "rule to detect Cactus Ransomware"
		author = "ShadowStackRe.com"
		date = "2024-01-18"
		Rule_Version = "v1"
		malware_type = "ransomware"
		malware_family = "Cactus"
		License = "MIT License, https://opensource.org/license/mit/"
		Hash = "9ec6d3bc07743d96b723174379620dd56c167c58a1e04dbfb7a392319647441a,c49b4faa6ac7b5c207410ed1e86d0f21c00f47a78c531a0a736266c436cc1c0a"
	strings:
		$strReadMe = "cAcTuS.readme.txt" wide
		$strLockExt = ".cts" wide
		$strTskName = "Updates Check Task" wide
		$strTskName2 = "Google Service Update"
		$strNTUSer = "ntuser.dat" wide
		$strNTUSer2 = "ntuser.log" wide
		$strBuilderName = "cactusbuilder"
	condition:
		uint16(0) == 0x5A4D and ($strReadMe and $strLockExt) and (1 of ($strTskName*)) and (1 of ($strNTUSer*)) or ($strBuilderName)
}

Community-contributed rules for Cactus, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Cactus is a ransomware threat group that has disclosed 157 victims in publicly accessible leak site data, representing 0.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Cactus in our dataset dates to January 2024.

Geographically, Cactus has targeted organisations in 20 countries. The most frequently targeted nation is United States with 97 victim organisations. Other heavily targeted nations include Canada, United Kingdom, France.

Industry-wise, Cactus shows a concentration in the Manufacturing, Business Services, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Cactus likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 157 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 157)

# Organization Country Sector Date
1 biagibros.com biagibros.com 🇺🇸 United States Transportation/Logistics Mar 21, 2025
2 fplfood.com fplfood.com 🇺🇸 United States Agriculture and Food Production Mar 21, 2025
3 optiline.com optiline.com 🇪🇪 Estonia Construction Mar 21, 2025
4 assaabloy.com assaabloy.com 🇸🇪 Sweden Manufacturing Mar 17, 2025
5 kyb.com kyb.com 🇯🇵 Japan Technology Mar 17, 2025
6 baillie.com baillie.com 🇺🇸 United States Construction Mar 12, 2025
7 rocketstores.com rocketstores.com 🇺🇸 United States Consumer Services Mar 12, 2025
8 tempel.com tempel.com 🇺🇸 United States Technology Mar 12, 2025
9 thermoid.com thermoid.com 🇺🇸 United States Manufacturing Mar 12, 2025
10 urban1.com urban1.com 🇺🇸 United States Technology Mar 12, 2025
11 quigleyeye.com quigleyeye.com 🇺🇸 United States Healthcare Mar 3, 2025
12 stanleyconsultants.com stanleyconsultants.com 🇺🇸 United States Business Services Feb 28, 2025
13 alphabaking.com alphabaking.com 🇺🇸 United States Agriculture and Food Production Feb 26, 2025
14 caltrol.com caltrol.com 🇺🇸 United States Technology Feb 26, 2025
15 holtcat.com holtcat.com 🇺🇸 United States Manufacturing Feb 26, 2025
16 bluedge.com bluedge.com 🇺🇸 United States Technology Feb 25, 2025
17 lifting.com lifting.com 🇺🇸 United States Manufacturing Feb 25, 2025
18 aiibeauty.com aiibeauty.com 🇺🇸 United States Consumer Services Feb 24, 2025
19 amalgamatedsugar.com amalgamatedsugar.com 🇺🇸 United States Agriculture and Food Production Feb 24, 2025
20 associatedasset.com associatedasset.com 🇺🇸 United States Financial Services Feb 24, 2025
21 branchgroup.com branchgroup.com 🇺🇸 United States Construction Feb 24, 2025
22 chfindustries.com chfindustries.com 🇺🇸 United States Manufacturing Feb 24, 2025
23 electrocraft.com electrocraft.com 🇺🇸 United States Technology Feb 24, 2025
24 everelgroup.com everelgroup.com 🇮🇹 Italy Manufacturing Feb 24, 2025
25 formanmills.com formanmills.com 🇺🇸 United States Consumer Services Feb 24, 2025
26 grede.com grede.com 🇺🇸 United States Manufacturing Feb 24, 2025
27 pace-usa.com pace-usa.com 🇺🇸 United States Transportation/Logistics Feb 24, 2025
28 regulvar.com regulvar.com 🇨🇦 Canada Construction Feb 24, 2025
29 steelwarehouse.com steelwarehouse.com 🇺🇸 United States Manufacturing Feb 24, 2025
30 newhorizonsbaking.com newhorizonsbaking.com 🇺🇸 United States Agriculture and Food Production Feb 20, 2025
31 bestbrands.com bestbrands.com 🇺🇸 United States Consumer Services Feb 18, 2025
32 midwayimporting.com midwayimporting.com 🇺🇸 United States Consumer Services Feb 18, 2025
33 revitalash.com revitalash.com 🇺🇸 United States Consumer Services Feb 18, 2025
34 uniekinc.com uniekinc.com 🇺🇸 United States Manufacturing Feb 18, 2025
35 almostfamousclothing.com almostfamousclothing.com 🇺🇸 United States Consumer Services Feb 17, 2025
36 kinseysinc.com kinseysinc.com 🇺🇸 United States Manufacturing Feb 17, 2025
37 ssmcoop.com ssmcoop.com 🇺🇸 United States Agriculture and Food Production Feb 17, 2025
38 steelerubber.com steelerubber.com 🇺🇸 United States Manufacturing Feb 17, 2025
39 This entry has been removed following a request from the company. 🇺🇸 United States Consumer Services Feb 17, 2025
40 britannicahome.com britannicahome.com 🇺🇸 United States Consumer Services Feb 12, 2025
41 curtisint.com curtisint.com 🇨🇦 Canada Technology Feb 12, 2025
42 uniquehd.com uniquehd.com 🇺🇸 United States Manufacturing Feb 12, 2025
43 northernresponse.com northernresponse.com 🇨🇦 Canada Consumer Services Feb 6, 2025
44 savoiesfoods.com savoiesfoods.com 🇺🇸 United States Agriculture and Food Production Feb 6, 2025
45 cornwelltools.com cornwelltools.com 🇺🇸 United States Consumer Services Feb 4, 2025
46 mgainnovation.com mgainnovation.com 🇺🇸 United States Technology Feb 4, 2025
47 rashtiandrashti.com rashtiandrashti.com 🇺🇸 United States Business Services Feb 4, 2025
48 alkodistributors.com alkodistributors.com 🇺🇸 United States Consumer Services Jan 30, 2025
49 jayaapparelgroup.com jayaapparelgroup.com 🇺🇸 United States Consumer Services Jan 30, 2025
50 johnpaulrichard.com johnpaulrichard.com 🇺🇸 United States Consumer Services Jan 30, 2025
51 sunrise-soya.com sunrise-soya.com 🇨🇦 Canada Agriculture and Food Production Jan 30, 2025
52 ttucorp.com ttucorp.com 🇺🇸 United States Technology Jan 30, 2025
53 vsstransportationgroup.com vsstransportationgroup.com 🇺🇸 United States Transportation/Logistics Jan 30, 2025
54 adveo.com adveo.com 🇫🇷 France Business Services Dec 23, 2024
55 awimc.com awimc.com 🇺🇸 United States Business Services Dec 23, 2024
56 galatachemicals.com galatachemicals.com 🇺🇸 United States Manufacturing Dec 23, 2024
57 ptcky.com ptcky.com 🇺🇸 United States Healthcare Dec 23, 2024
58 massdevelopment.com massdevelopment.com 🇺🇸 United States Financial Services Dec 18, 2024
59 ottosimon.co.uk ottosimon.co.uk 🇬🇧 United Kingdom Business Services Nov 8, 2024
60 lsst.ac lsst.ac 🇬🇧 United Kingdom Technology Nov 1, 2024
61 lumiplan.com lumiplan.com 🇫🇷 France Technology Nov 1, 2024
62 hacla.org hacla.org 🇺🇸 United States Public Sector Oct 31, 2024
63 bcllegal.com bcllegal.com 🇬🇧 United Kingdom Business Services Oct 24, 2024
64 picsolve.com picsolve.com 🇺🇸 United States Hospitality and Tourism Oct 24, 2024
65 synertrade.com synertrade.com 🇫🇷 France Technology Oct 16, 2024
66 corporatejobbank.com corporatejobbank.com 🇺🇸 United States Business Services Oct 8, 2024
67 matki.co.uk matki.co.uk 🇬🇧 United Kingdom Manufacturing Oct 8, 2024
68 www.galab.com galab.com 🇩🇪 Germany Agriculture and Food Production Oct 1, 2024
69 actionfirepros.com actionfirepros.com 🇺🇸 United States Business Services Sep 27, 2024
70 hindlegroup.com hindlegroup.com 🇬🇧 United Kingdom Business Services Sep 25, 2024
71 kjtait.com kjtait.com 🇬🇧 United Kingdom Business Services Sep 25, 2024
72 www.amchar.com amchar.com 🇺🇸 United States Business Services Sep 25, 2024
73 ten8fire.com ten8fire.com 🇺🇸 United States Manufacturing Sep 23, 2024
74 natcoglobal.com natcoglobal.com 🇺🇸 United States Manufacturing Sep 17, 2024
75 peerlessumbrella.com peerlessumbrella.com 🇺🇸 United States Manufacturing Sep 17, 2024
76 thomas-lloyd.com thomas-lloyd.com 🇺🇸 United States Financial Services Sep 17, 2024
77 champeau.com champeau.com 🇨🇦 Canada Business Services Sep 6, 2024
78 riomarineinc.com riomarineinc.com 🇺🇸 United States Business Services Sep 6, 2024
79 balboabayresort.com balboabayresort.com 🇺🇸 United States Hospitality and Tourism Sep 4, 2024
80 simson-maxwell.com simson-maxwell.com 🇨🇦 Canada Energy Sep 4, 2024
81 flodraulic.com flodraulic.com 🇺🇸 United States Manufacturing Sep 3, 2024
82 mcphillips.co.uk mcphillips.co.uk 🇬🇧 United Kingdom Business Services Sep 3, 2024
83 rangeramerican.com rangeramerican.com PR Business Services Sep 3, 2024
84 securityinstrument.com securityinstrument.com 🇺🇸 United States Technology Aug 27, 2024
85 mihlfeld.com mihlfeld.com 🇺🇸 United States Transportation/Logistics Aug 8, 2024
86 tibaitservices.com tibaitservices.com 🇲🇽 Mexico Technology Aug 8, 2024
87 exco-solutions.com exco-solutions.com 🇩🇪 Germany Manufacturing Aug 5, 2024
88 dahlvalve.com dahlvalve.com 🇨🇦 Canada Manufacturing Aug 1, 2024
89 chubb-bulleid.co.uk chubb-bulleid.co.uk 🇬🇧 United Kingdom Business Services Jul 30, 2024
90 demos.fr demos.fr 🇫🇷 France Technology Jul 30, 2024
91 denkaiamerica.com denkaiamerica.com 🇺🇸 United States Manufacturing Jul 30, 2024
92 leonardssyrups.com leonardssyrups.com 🇺🇸 United States Business Services Jul 30, 2024
93 westernwyomingbeverages.com westernwyomingbeverages.com 🇺🇸 United States Business Services Jul 30, 2024
94 isometrix.com isometrix.com 🇺🇸 United States Technology Jul 17, 2024
95 verco.co.uk verco.co.uk 🇬🇧 United Kingdom Manufacturing Jul 16, 2024
96 hydmech.com hydmech.com 🇨🇦 Canada Manufacturing Jun 24, 2024
97 westfalia-automotive.com westfalia-automotive.com 🇩🇪 Germany Manufacturing Jun 24, 2024
98 daystar.com daystar.com 🇺🇸 United States Consumer Services Jun 23, 2024
99 deskcenter.com deskcenter.com 🇩🇪 Germany Technology Jun 23, 2024
100 fbttransport.com fbttransport.com 🇺🇸 United States Transportation/Logistics Jun 23, 2024

Frequently Asked Questions

What is Cactus ransomware?

Cactus is a ransomware threat group that has claimed 157 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Cactus attacked?

Cactus has claimed 157 victims in our database, representing 0.7% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, France.

Which countries does Cactus target?

Cactus has attacked organizations in 20 countries. The top targeted countries are: United States, Canada, United Kingdom, France.

Which industries does Cactus target?

Cactus most frequently targets the Manufacturing, Business Services, Technology sectors based on victim disclosures in our database.

Is Cactus still active?

Cactus's most recent victim disclosure in our database was on March 21, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.