Cactus ransomware evades antivirus with self-encryption.

1 min read
Source: BleepingComputer
Cactus ransomware evades antivirus with self-encryption.
Photo: BleepingComputer
TL;DR Summary

A new ransomware operation called Cactus has been exploiting vulnerabilities in VPN appliances for initial access to networks of “large commercial entities.” Cactus encrypts itself to evade antivirus and uses a batch script to obtain the encryptor binary using 7-Zip. The ransomware operation uses a unique AES key known only to the attackers to decrypt the ransomware's configuration file and the public RSA key needed to encrypt files. Cactus also steals data from the victim and threatens to publish the stolen files unless they get paid.

Share this article

Reading Insights

Total Reads

0

Unique Readers

13

Time Saved

4 min

vs 5 min read

Condensed

91%

96486 words

Want the full story? Read the original article

Read on BleepingComputer