Cactus Ransomware
TrackedThreat actor group tracked in the global ransomware database · Last disclosure: Mar 21, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Cactus and from this database. Figures and technique mappings are quoted from the source data, not inferred.
The Cactus ransomware emerged in March 2023 and has infected a reported 157 victims across 20 countries, targeting sectors like manufacturing, business services, and technology.
Who Cactus is
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox. Source: https://github.com/crocodyli/ThreatActors-TTPs
Recorded activity
Disclosures attributed to Cactus in this database run from January 2024 to March 2025, totalling 157 victims — 0.7% of everything tracked here. Cactus has listed victims in 20 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Manufacturing, Business Services, Technology.
How Cactus is documented to operate
Exploit Public-Facing Application T1190 Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →Software Deployment Tools T1072 Execution Lateral Movement
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems.
Mitigations: Remote Data Storage, Limit Software Installation, User Training, Network Segmentation, Password Policies, User Account Management
MITRE ATT&CK reference →Create Account T1136 Persistence
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system. Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.
Mitigations: Operating System Configuration, Network Segmentation, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →Obfuscated Files or Information T1027 Stealth
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.
Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit
MITRE ATT&CK reference →Disable or Modify Tools T1685 Defense Impairment
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Mitigations: Execution Prevention, User Account Management, Restrict File and Directory Permissions, Restrict Registry Permissions, Software Configuration, Audit
MITRE ATT&CK reference →OS Credential Dumping T1003 Credential Access
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Mitigations: Encrypt Sensitive Information, Behavior Prevention on Endpoint, Password Policies, User Training, Privileged Account Management, Privileged Process Integrity
MITRE ATT&CK reference →Credentials from Web Browsers T1555.003 Credential Access
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <codeAppData\Local\Google\Chrome\User Data\Default\Login Data</code and executing a SQL query: <codeSELECT actionurl, usernamevalue, passwordvalue FROM logins;</code.
Mitigations: Restrict Web-Based Content, User Training, Password Policies, User Account Management, Update Software
MITRE ATT&CK reference →Remote System Discovery T1018 Discovery
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <codenet view</code using Net, or, on ESXi servers, esxcli network diag ping. Adversaries may also analyze data from local host files (ex: <codeC:\Windows\System32\Drivers\etc\hosts</code or <code/etc/hosts</code) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Cactus across its recorded activity. They describe the group overall, not any single incident.
Tooling observed in Cactus operations
- Nmap
- SoftPerfect NetScan
- RClone
- Chisel
- Cobalt Strike
- AnyDesk
- Splashtop
- SuperOps
Software reported in use by Cactus. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Indicators of compromise
- 466a8e120c75770ecbc0c73f0439d304
- 718d56fd19bbaf5e78c03e096dae64ca
- 586a7991bb097e7c4ef676b180f65a6a
- 7fa55bf92073ca2115d70641566ce89b
- ccb993b425257228bd48c0aac20d5027
- 28103f745f58a2af71d327012846c022
- [email protected]
- [email protected]
- [email protected]
Showing a sample of 50 MD5, 3 EMAIL on file. Hashes and network indicators published for Cactus. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
cactus.yar
rule CactusRule
{
strings:
$cactusStr = “CaCtUs.ReAdMe.txt”
$cactusHex = { 43 61 43 74 55 73 2e 52 65 41 64 4d 65 2e 74 78 74 }
condition:
$cactusStr or $cactusHex
}
rule CactusRansomware {
meta:
description = "rule to detect Cactus Ransomware"
author = "ShadowStackRe.com"
date = "2024-01-18"
Rule_Version = "v1"
malware_type = "ransomware"
malware_family = "Cactus"
License = "MIT License, https://opensource.org/license/mit/"
Hash = "9ec6d3bc07743d96b723174379620dd56c167c58a1e04dbfb7a392319647441a,c49b4faa6ac7b5c207410ed1e86d0f21c00f47a78c531a0a736266c436cc1c0a"
strings:
$strReadMe = "cAcTuS.readme.txt" wide
$strLockExt = ".cts" wide
$strTskName = "Updates Check Task" wide
$strTskName2 = "Google Service Update"
$strNTUSer = "ntuser.dat" wide
$strNTUSer2 = "ntuser.log" wide
$strBuilderName = "cactusbuilder"
condition:
uint16(0) == 0x5A4D and ($strReadMe and $strLockExt) and (1 of ($strTskName*)) and (1 of ($strNTUSer*)) or ($strBuilderName)
}
Community-contributed rules for Cactus, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Cactus is a ransomware threat group that has disclosed 157 victims in publicly accessible leak site data, representing 0.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Cactus in our dataset dates to January 2024.
Geographically, Cactus has targeted organisations in 20 countries. The most frequently targeted nation is United States with 97 victim organisations. Other heavily targeted nations include Canada, United Kingdom, France.
Industry-wise, Cactus shows a concentration in the Manufacturing, Business Services, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Cactus likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 157 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 157)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | biagibros.com biagibros.com | 🇺🇸 United States | Transportation/Logistics | Mar 21, 2025 |
| 2 | fplfood.com fplfood.com | 🇺🇸 United States | Agriculture and Food Production | Mar 21, 2025 |
| 3 | optiline.com optiline.com | 🇪🇪 Estonia | Construction | Mar 21, 2025 |
| 4 | assaabloy.com assaabloy.com | 🇸🇪 Sweden | Manufacturing | Mar 17, 2025 |
| 5 | kyb.com kyb.com | 🇯🇵 Japan | Technology | Mar 17, 2025 |
| 6 | baillie.com baillie.com | 🇺🇸 United States | Construction | Mar 12, 2025 |
| 7 | rocketstores.com rocketstores.com | 🇺🇸 United States | Consumer Services | Mar 12, 2025 |
| 8 | tempel.com tempel.com | 🇺🇸 United States | Technology | Mar 12, 2025 |
| 9 | thermoid.com thermoid.com | 🇺🇸 United States | Manufacturing | Mar 12, 2025 |
| 10 | urban1.com urban1.com | 🇺🇸 United States | Technology | Mar 12, 2025 |
| 11 | quigleyeye.com quigleyeye.com | 🇺🇸 United States | Healthcare | Mar 3, 2025 |
| 12 | stanleyconsultants.com stanleyconsultants.com | 🇺🇸 United States | Business Services | Feb 28, 2025 |
| 13 | alphabaking.com alphabaking.com | 🇺🇸 United States | Agriculture and Food Production | Feb 26, 2025 |
| 14 | caltrol.com caltrol.com | 🇺🇸 United States | Technology | Feb 26, 2025 |
| 15 | holtcat.com holtcat.com | 🇺🇸 United States | Manufacturing | Feb 26, 2025 |
| 16 | bluedge.com bluedge.com | 🇺🇸 United States | Technology | Feb 25, 2025 |
| 17 | lifting.com lifting.com | 🇺🇸 United States | Manufacturing | Feb 25, 2025 |
| 18 | aiibeauty.com aiibeauty.com | 🇺🇸 United States | Consumer Services | Feb 24, 2025 |
| 19 | amalgamatedsugar.com amalgamatedsugar.com | 🇺🇸 United States | Agriculture and Food Production | Feb 24, 2025 |
| 20 | associatedasset.com associatedasset.com | 🇺🇸 United States | Financial Services | Feb 24, 2025 |
| 21 | branchgroup.com branchgroup.com | 🇺🇸 United States | Construction | Feb 24, 2025 |
| 22 | chfindustries.com chfindustries.com | 🇺🇸 United States | Manufacturing | Feb 24, 2025 |
| 23 | electrocraft.com electrocraft.com | 🇺🇸 United States | Technology | Feb 24, 2025 |
| 24 | everelgroup.com everelgroup.com | 🇮🇹 Italy | Manufacturing | Feb 24, 2025 |
| 25 | formanmills.com formanmills.com | 🇺🇸 United States | Consumer Services | Feb 24, 2025 |
| 26 | grede.com grede.com | 🇺🇸 United States | Manufacturing | Feb 24, 2025 |
| 27 | pace-usa.com pace-usa.com | 🇺🇸 United States | Transportation/Logistics | Feb 24, 2025 |
| 28 | regulvar.com regulvar.com | 🇨🇦 Canada | Construction | Feb 24, 2025 |
| 29 | steelwarehouse.com steelwarehouse.com | 🇺🇸 United States | Manufacturing | Feb 24, 2025 |
| 30 | newhorizonsbaking.com newhorizonsbaking.com | 🇺🇸 United States | Agriculture and Food Production | Feb 20, 2025 |
| 31 | bestbrands.com bestbrands.com | 🇺🇸 United States | Consumer Services | Feb 18, 2025 |
| 32 | midwayimporting.com midwayimporting.com | 🇺🇸 United States | Consumer Services | Feb 18, 2025 |
| 33 | revitalash.com revitalash.com | 🇺🇸 United States | Consumer Services | Feb 18, 2025 |
| 34 | uniekinc.com uniekinc.com | 🇺🇸 United States | Manufacturing | Feb 18, 2025 |
| 35 | almostfamousclothing.com almostfamousclothing.com | 🇺🇸 United States | Consumer Services | Feb 17, 2025 |
| 36 | kinseysinc.com kinseysinc.com | 🇺🇸 United States | Manufacturing | Feb 17, 2025 |
| 37 | ssmcoop.com ssmcoop.com | 🇺🇸 United States | Agriculture and Food Production | Feb 17, 2025 |
| 38 | steelerubber.com steelerubber.com | 🇺🇸 United States | Manufacturing | Feb 17, 2025 |
| 39 | This entry has been removed following a request from the company. | 🇺🇸 United States | Consumer Services | Feb 17, 2025 |
| 40 | britannicahome.com britannicahome.com | 🇺🇸 United States | Consumer Services | Feb 12, 2025 |
| 41 | curtisint.com curtisint.com | 🇨🇦 Canada | Technology | Feb 12, 2025 |
| 42 | uniquehd.com uniquehd.com | 🇺🇸 United States | Manufacturing | Feb 12, 2025 |
| 43 | northernresponse.com northernresponse.com | 🇨🇦 Canada | Consumer Services | Feb 6, 2025 |
| 44 | savoiesfoods.com savoiesfoods.com | 🇺🇸 United States | Agriculture and Food Production | Feb 6, 2025 |
| 45 | cornwelltools.com cornwelltools.com | 🇺🇸 United States | Consumer Services | Feb 4, 2025 |
| 46 | mgainnovation.com mgainnovation.com | 🇺🇸 United States | Technology | Feb 4, 2025 |
| 47 | rashtiandrashti.com rashtiandrashti.com | 🇺🇸 United States | Business Services | Feb 4, 2025 |
| 48 | alkodistributors.com alkodistributors.com | 🇺🇸 United States | Consumer Services | Jan 30, 2025 |
| 49 | jayaapparelgroup.com jayaapparelgroup.com | 🇺🇸 United States | Consumer Services | Jan 30, 2025 |
| 50 | johnpaulrichard.com johnpaulrichard.com | 🇺🇸 United States | Consumer Services | Jan 30, 2025 |
| 51 | sunrise-soya.com sunrise-soya.com | 🇨🇦 Canada | Agriculture and Food Production | Jan 30, 2025 |
| 52 | ttucorp.com ttucorp.com | 🇺🇸 United States | Technology | Jan 30, 2025 |
| 53 | vsstransportationgroup.com vsstransportationgroup.com | 🇺🇸 United States | Transportation/Logistics | Jan 30, 2025 |
| 54 | adveo.com adveo.com | 🇫🇷 France | Business Services | Dec 23, 2024 |
| 55 | awimc.com awimc.com | 🇺🇸 United States | Business Services | Dec 23, 2024 |
| 56 | galatachemicals.com galatachemicals.com | 🇺🇸 United States | Manufacturing | Dec 23, 2024 |
| 57 | ptcky.com ptcky.com | 🇺🇸 United States | Healthcare | Dec 23, 2024 |
| 58 | massdevelopment.com massdevelopment.com | 🇺🇸 United States | Financial Services | Dec 18, 2024 |
| 59 | ottosimon.co.uk ottosimon.co.uk | 🇬🇧 United Kingdom | Business Services | Nov 8, 2024 |
| 60 | lsst.ac lsst.ac | 🇬🇧 United Kingdom | Technology | Nov 1, 2024 |
| 61 | lumiplan.com lumiplan.com | 🇫🇷 France | Technology | Nov 1, 2024 |
| 62 | hacla.org hacla.org | 🇺🇸 United States | Public Sector | Oct 31, 2024 |
| 63 | bcllegal.com bcllegal.com | 🇬🇧 United Kingdom | Business Services | Oct 24, 2024 |
| 64 | picsolve.com picsolve.com | 🇺🇸 United States | Hospitality and Tourism | Oct 24, 2024 |
| 65 | synertrade.com synertrade.com | 🇫🇷 France | Technology | Oct 16, 2024 |
| 66 | corporatejobbank.com corporatejobbank.com | 🇺🇸 United States | Business Services | Oct 8, 2024 |
| 67 | matki.co.uk matki.co.uk | 🇬🇧 United Kingdom | Manufacturing | Oct 8, 2024 |
| 68 | www.galab.com galab.com | 🇩🇪 Germany | Agriculture and Food Production | Oct 1, 2024 |
| 69 | actionfirepros.com actionfirepros.com | 🇺🇸 United States | Business Services | Sep 27, 2024 |
| 70 | hindlegroup.com hindlegroup.com | 🇬🇧 United Kingdom | Business Services | Sep 25, 2024 |
| 71 | kjtait.com kjtait.com | 🇬🇧 United Kingdom | Business Services | Sep 25, 2024 |
| 72 | www.amchar.com amchar.com | 🇺🇸 United States | Business Services | Sep 25, 2024 |
| 73 | ten8fire.com ten8fire.com | 🇺🇸 United States | Manufacturing | Sep 23, 2024 |
| 74 | natcoglobal.com natcoglobal.com | 🇺🇸 United States | Manufacturing | Sep 17, 2024 |
| 75 | peerlessumbrella.com peerlessumbrella.com | 🇺🇸 United States | Manufacturing | Sep 17, 2024 |
| 76 | thomas-lloyd.com thomas-lloyd.com | 🇺🇸 United States | Financial Services | Sep 17, 2024 |
| 77 | champeau.com champeau.com | 🇨🇦 Canada | Business Services | Sep 6, 2024 |
| 78 | riomarineinc.com riomarineinc.com | 🇺🇸 United States | Business Services | Sep 6, 2024 |
| 79 | balboabayresort.com balboabayresort.com | 🇺🇸 United States | Hospitality and Tourism | Sep 4, 2024 |
| 80 | simson-maxwell.com simson-maxwell.com | 🇨🇦 Canada | Energy | Sep 4, 2024 |
| 81 | flodraulic.com flodraulic.com | 🇺🇸 United States | Manufacturing | Sep 3, 2024 |
| 82 | mcphillips.co.uk mcphillips.co.uk | 🇬🇧 United Kingdom | Business Services | Sep 3, 2024 |
| 83 | rangeramerican.com rangeramerican.com | PR | Business Services | Sep 3, 2024 |
| 84 | securityinstrument.com securityinstrument.com | 🇺🇸 United States | Technology | Aug 27, 2024 |
| 85 | mihlfeld.com mihlfeld.com | 🇺🇸 United States | Transportation/Logistics | Aug 8, 2024 |
| 86 | tibaitservices.com tibaitservices.com | 🇲🇽 Mexico | Technology | Aug 8, 2024 |
| 87 | exco-solutions.com exco-solutions.com | 🇩🇪 Germany | Manufacturing | Aug 5, 2024 |
| 88 | dahlvalve.com dahlvalve.com | 🇨🇦 Canada | Manufacturing | Aug 1, 2024 |
| 89 | chubb-bulleid.co.uk chubb-bulleid.co.uk | 🇬🇧 United Kingdom | Business Services | Jul 30, 2024 |
| 90 | demos.fr demos.fr | 🇫🇷 France | Technology | Jul 30, 2024 |
| 91 | denkaiamerica.com denkaiamerica.com | 🇺🇸 United States | Manufacturing | Jul 30, 2024 |
| 92 | leonardssyrups.com leonardssyrups.com | 🇺🇸 United States | Business Services | Jul 30, 2024 |
| 93 | westernwyomingbeverages.com westernwyomingbeverages.com | 🇺🇸 United States | Business Services | Jul 30, 2024 |
| 94 | isometrix.com isometrix.com | 🇺🇸 United States | Technology | Jul 17, 2024 |
| 95 | verco.co.uk verco.co.uk | 🇬🇧 United Kingdom | Manufacturing | Jul 16, 2024 |
| 96 | hydmech.com hydmech.com | 🇨🇦 Canada | Manufacturing | Jun 24, 2024 |
| 97 | westfalia-automotive.com westfalia-automotive.com | 🇩🇪 Germany | Manufacturing | Jun 24, 2024 |
| 98 | daystar.com daystar.com | 🇺🇸 United States | Consumer Services | Jun 23, 2024 |
| 99 | deskcenter.com deskcenter.com | 🇩🇪 Germany | Technology | Jun 23, 2024 |
| 100 | fbttransport.com fbttransport.com | 🇺🇸 United States | Transportation/Logistics | Jun 23, 2024 |
Frequently Asked Questions
What is Cactus ransomware?
Cactus is a ransomware threat group that has claimed 157 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Cactus attacked?
Cactus has claimed 157 victims in our database, representing 0.7% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, France.
Which countries does Cactus target?
Cactus has attacked organizations in 20 countries. The top targeted countries are: United States, Canada, United Kingdom, France.
Which industries does Cactus target?
Cactus most frequently targets the Manufacturing, Business Services, Technology sectors based on victim disclosures in our database.
Is Cactus still active?
Cactus's most recent victim disclosure in our database was on March 21, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.