Cactus ransomware evades antivirus with self-encryption.

TL;DR Summary
A new ransomware operation called Cactus has been exploiting vulnerabilities in VPN appliances for initial access to networks of “large commercial entities.” Cactus encrypts itself to evade antivirus and uses a batch script to obtain the encryptor binary using 7-Zip. The ransomware operation uses a unique AES key known only to the attackers to decrypt the ransomware's configuration file and the public RSA key needed to encrypt files. Cactus also steals data from the victim and threatens to publish the stolen files unless they get paid.
New Cactus ransomware encrypts itself to evade antivirus BleepingComputer
Reading Insights
Total Reads
0
Unique Readers
13
Time Saved
4 min
vs 5 min read
Condensed
91%
964 → 86 words
Want the full story? Read the original article
Read on BleepingComputer