Cactus ransomware evades antivirus with self-encryption.

1 min read
Source: BleepingComputer
Cactus ransomware evades antivirus with self-encryption.
Photo: BleepingComputer
TL;DR

A new ransomware operation called Cactus has been exploiting vulnerabilities in VPN appliances for initial access to networks of “large commercial entities.” Cactus encrypts itself to evade antivirus and uses a batch script to obtain the encryptor binary using 7-Zip. The ransomware operation uses a unique AES key known only to the attackers to decrypt the ransomware's configuration file and the public RSA key needed to encrypt files. Cactus also steals data from the victim and threatens to publish the stolen files unless they get paid.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer