Cactus
Aliases: Cactus ransomware
Source profile review date: 2026-06-21
Added to the source registry: 2023-07-20 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
Executive summary
Cactus is a known double-extortion group notable for VPN/edge access, encryptor self-protection and attacks where data exfiltration and recovery disruption are central.
Cactus is technically important because the group can protect payloads or deliver them encrypted to evade detection, and operationally important because of edge/VPN risk, data theft and enterprise impact.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Executive summary
Cactus is a mature ransomware group that affects organisations through known enterprise weaknesses: vulnerable or poorly monitored edge equipment, VPN access, credentials, lateral movement, data theft and encryption. The group is relevant because it combines technical evasion with ordinary administration mistakes.
A notable point from public analysis is that Cactus can protect payloads or deliver them encrypted, making simple static detection less reliable. Organisations must therefore detect execution, behaviour and the attack chain.
For visitors, the main lesson is that edge security and recoverability must be assessed together. A vulnerable VPN or appliance is not only an access point; it can be the start of data theft, domain compromise and an attack on backups.
Group and development
Cactus became visible in 2023 and remained relevant in public ransomware feeds. The group uses double extortion and claims victims across multiple sectors. The operation fits human-operated ransomware with technical preparation.
Public reporting linked Cactus in several analyses to abuse of VPN equipment or vulnerable external access. That means perimeter management, patching and logging of edge appliances are crucial.
The group shows that modern ransomware does not always need new exploits. Old vulnerabilities, missing MFA, weak segmentation and broad administrator rights remain enough.
Methods and attack chain
The attack can start through VPN or internet-facing systems. Discovery then follows across the domain, servers, shares, backups and security tools. The actor uses valid credentials or increases privileges to move laterally.
Cactus is known for attention to payload evasion. If the encryptor is delivered encrypted or protected, detection before execution becomes harder. Command line, parent process, file location and timing therefore matter.
Data is collected and exfiltration prepared before encryption starts. Watch for archives, staging directories, Rclone or cloud sync, unusual outbound volumes and access to sensitive shares outside normal patterns.
Impact preparation may include security-tool impairment, service stops, shadow-copy deletion and access to backups. Investigation must check whether backup administration and virtualisation were accessed.
Known IOCs and artefacts
Artefacts include Cactus ransom notes, encrypted payload containers, execution of encryptors with specific command lines, leak-site claims, data samples, staging files and remote-access traces.
Because payloads can be protected, hashes are not enough. Detect execution from unusual paths, scripts that decrypt or start payloads, service stops, mass file writes and network transfer.
Edge logs are crucial. VPN authentication, appliance logs, SSO, MFA events and firewall flows often determine how the actor entered.
Victim pattern and lessons
Cactus victims show broad enterprise impact. The common factor is often not sector, but exposure: edge equipment, remote access, data-rich servers and recovery dependency.
The lesson is that appliance patching and logging must be mature. Many organisations patch servers better than VPN or security appliances, even though those are internet-facing.
A second lesson is that payload evasion works only when earlier phases are missed. Organisations that detect access, privilege use and data staging do not need to wait for the encryptor.
How to defend
Patch and monitor edge equipment. VPNs, firewalls, remote gateways and appliances must have MFA, logging, firmware management and anomaly detection.
Detect ransomware preparation. Archiving, exfiltration, service stops, security tampering and backup-console access are stronger than hash detection alone.
Segment recovery platforms. Backup servers, hypervisors and storage must not be reachable with ordinary domain accounts or from ordinary server segments.
Specific hunts
For Cactus, hunt first on edge and VPN access. Look for appliance logins, firmware vulnerabilities, new sessions, MFA bypass, unusual user agents and access from hosting providers or countries that do not fit.
Check payload preparation. Cactus is known for encryptor evasion; look for scripts that decrypt payloads, unusual command lines, execution from temporary folders, service stops and mass file writes.
Hunt for data staging and recovery impact. Look for archives, outbound transfers, Rclone or cloud sync, vssadmin/wbadmin/bcdedit, backup-console logins and hypervisor access.
Exposure and prevention
Exposure scans must treat VPNs, firewalls, remote gateways and appliances as first-class assets. Patch status, MFA, logging and management-interface reachability are crucial.
Check whether edge equipment forwards logs centrally. Without appliance logs, initial access cannot be proven and the investigation starts too late at encryption.
Restrict server outbound traffic. If a server can upload large archives without inspection, Cactus receives data extortion almost for free.
Sources and uncertainty
Cactus has a reasonable technical source base, but incident routes remain variable. Not every Cactus claim starts through the same VPN or the same payload variant.
Payload evasion must be treated as a technical focus, but not the only focus. The actor still needs access, privileges and data.
Every update should state which layer is confirmed: edge access, payload, data theft, encryption, backup impact or leak-site claim.
Scenario for leadership and SOC
A Cactus scenario often starts with an edge service or VPN. The actor uses a vulnerability or credential, moves internally and prepares payloads that are not easily recognised statically.
The SOC must therefore combine edge logs and endpoint behaviour. A suspicious VPN login becomes much stronger evidence when the same account later shows discovery, archiving or backup-console access.
For leadership, Cactus shows that patch management and recovery management belong together. A vulnerable appliance can lead directly to the question whether backups are still trustworthy.
What the visitor should check concretely
Check all edge devices for firmware, MFA, logging and management interface exposure. Firewalls and VPNs are crown-jewel systems, not side issues.
Check whether payload evasion is covered by behavioural detection. Detect service stops, mass writes, strange command lines and execution from temporary folders.
Check whether backups are immutable and whether restore tests are possible without domain admin. That determines real recoverability.
Relationship with Amuneth Exposure
Exposure is especially relevant for Cactus because edge vulnerabilities are often the first step. A scan showing an outdated VPN, firewall or web gateway is direct ransomware prevention.
Reports must prioritise internet-facing systems with management functions. A vulnerable CMS is serious; a vulnerable VPN with domain access is critical.
The customer must be able to infer from the report which finding should be closed first, not only which CVE has the highest score.
Additional defensive notes
Cactus requires mature edge management. VPNs, firewalls and gateways are sometimes treated as infrastructure and fall outside ordinary patch reports. For ransomware they are often the front door.
For every edge appliance, define owner, firmware version, log forwarding, administrator rights and emergency procedure for compromise. Without that information, containment is slow.
Because Cactus can use payload evasion, behaviour must lead. An unknown encryptor can still be stopped when the organisation quickly sees service stops, shadow-copy deletion, mass writes and backup-console access.
After a Cactus-like incident, always check whether the appliance itself can still be trusted. Restoring only backend servers is insufficient when the original access still exists or the appliance configuration was changed.
Additional operational questions
For Cactus, every edge appliance must have an owner, patch rhythm and log destination. Without those three facts, the device is not managed, only present.
Check whether VPN accounts do not automatically provide broad internal access. A successful login must not immediately expose file servers, domain controllers and backup administration.
When Cactus is suspected, always investigate whether payload preparation has already occurred. An encrypted or protected payload can be ready before encryption becomes visible. Look for scripts, temporary files, strange command lines and service changes.
Final checkpoint
A final checkpoint for Cactus is validation of the original access. If the entry was a VPN or appliance, that layer itself must be investigated, patched, configured and sometimes replaced before recovery is trustworthy. Otherwise an actor can reuse the same route after recovery and the incident only appears resolved.
Additional closing note
After Cactus containment, perform a configuration review of edge equipment. Check local accounts, API keys, VPN profiles, firewall rules, firmware integrity and logging settings. A compromised appliance can otherwise become the entry point again after recovery.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| technique | encrypted or protected ransomware payload execution | public Cactus analysis | Statische detectie alleen is onvoldoende. |
| technique | VPN or edge access as initial access path | public reporting | Controleer appliance logs en MFA. |
| behavior | double extortion with data staging and leak-site pressure | public Cactus reporting | Data en encryptie samen onderzoeken. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.