CACTUS Ransomware Evades Antivirus and Exploits VPN Flaws to Infiltrate Networks

1 min read
Source: The Hacker News
CACTUS Ransomware Evades Antivirus and Exploits VPN Flaws to Infiltrate Networks
Photo: The Hacker News
TL;DR Summary

Cybersecurity researchers have discovered a new ransomware strain called CACTUS that exploits known flaws in VPN appliances to infiltrate targeted networks. The ransomware has been observed targeting large commercial entities since March 2023, using double extortion tactics to steal sensitive data prior to encryption. CACTUS actors attempt to enumerate local and network user accounts before creating new user accounts and deploying the ransomware encryptor via scheduled tasks. The ransomware also utilizes Cobalt Strike and a tunneling tool referred to as Chisel for command-and-control, alongside remote monitoring and management (RMM) software like AnyDesk to push files to the infected hosts.

Share this article

Reading Insights

Total Reads

0

Unique Readers

19

Time Saved

2 min

vs 3 min read

Condensed

82%

55499 words

Want the full story? Read the original article

Read on The Hacker News