CACTUS Ransomware Evades Antivirus and Exploits VPN Flaws to Infiltrate Networks

Cybersecurity researchers have discovered a new ransomware strain called CACTUS that exploits known flaws in VPN appliances to infiltrate targeted networks. The ransomware has been observed targeting large commercial entities since March 2023, using double extortion tactics to steal sensitive data prior to encryption. CACTUS actors attempt to enumerate local and network user accounts before creating new user accounts and deploying the ransomware encryptor via scheduled tasks. The ransomware also utilizes Cobalt Strike and a tunneling tool referred to as Chisel for command-and-control, alongside remote monitoring and management (RMM) software like AnyDesk to push files to the infected hosts.
- New Ransomware Strain 'CACTUS' Exploits VPN Flaws to Infiltrate Networks The Hacker News
- This devious new ransomware encrypts itself to avoid your antivirus TechRadar
- New ransomware group CACTUS abuses remote management tools for persistence CSO Online
- New Cactus ransomware encrypts itself to evade antivirus BleepingComputer
- View Full Coverage on Google News
Reading Insights
0
19
2 min
vs 3 min read
82%
554 → 99 words
Want the full story? Read the original article
Read on The Hacker News