The Stealthy CACTUS Ransomware Menace: Exploiting VPN Appliance Flaws and Targeting Large Corporations

Ransomware is a growing concern for companies of all sizes, and cybersecurity researchers have recently shed light on a new strain called CACTUS. This ransomware has been targeting large commercial entities since March 2021, and it has been observed to leverage known flaws in VPN appliances to gain initial access to targeted networks. Once inside, it employs double extortion tactics to steal sensitive data and demands payment in exchange for a decryption key.

Exploitation of vulnerable VPN devices sets the stage

CACTUS begins its attack by exploiting known vulnerabilities in VPN devices to set up an SSH backdoor. Once this initial access is established, the attacker executes a series of PowerShell commands to conduct network scanning and identify a list of machines to encrypt. These commands also allow the attacker to maintain persistent access to the network, making it more difficult for the victim to detect and remove the ransomware.

Using sophisticated tools for command and control

CACTUS also utilizes sophisticated tools for command and control, including the popular penetration testing framework Cobalt Strike and a tunneling tool referred to as Chisel. The ransomware authors also make use of Remote Monitoring and Management (RMM) software like AnyDesk, allowing them to remotely control the infected machines and monitor their progress.

A unique batch script evades detection

One unique aspect of CACTUS is the use of a batch script to extract the ransomware binary with 7-Zip. This process makes it harder to detect as the ransomware essentially encrypts itself, removing the .7z archive before executing the payload. This technique allows CACTUS to evade antivirus and network monitoring tools, making it more challenging for defenders to detect and remove.

Insights from cybersecurity experts

Laurie Iacono, Associate Managing Director for Cyber Risk at Kroll, commented on the unique features of CACTUS. She notes that the ransomware’s ability to encrypt itself makes it more challenging to detect, and that this demonstrates the importance of continual adaptation by cybersecurity professionals to keep up with evolving threats.

Comparison to other ransomware families

The emergence of CACTUS comes just days after Trend Micro shed light on another type of ransomware known as Rapture. This new ransomware shares some similarities with other families, such as Paradise. The use of vulnerable public-facing websites and servers is a common tactic for ransomware authors looking to gain access to corporate networks. This makes it essential for organizations to keep their systems up-to-date and enforce the principle of least privilege (PoLP).

The rising trend of new ransomware families

CACTUS and Rapture are the latest additions to a long list of new ransomware families that have come to light in recent weeks. Other examples include Gazprom, BlackBit, UNIZA, Akira, and a NoCry ransomware variant called Kadavro Vector. This trend demonstrates the continued evolution of ransomware as a significant threat to organizations worldwide.

The emergence of CACTUS and other new ransomware families highlights the critical need for organizations to stay vigilant and proactive in their approach to cybersecurity. Companies must prioritize continuous monitoring of their systems, implement regular patching and updates, and enforce the Principle of Least Privilege (PoLP) to limit the impact of ransomware attacks. As ransomware authors continue to develop new tactics and tools, it is essential for defenders to remain one step ahead and continuously adapt their strategies to keep pace with evolving threats.

Explore more

Demand to Resign Before Offer Letter Sparks Job Seeker Concern

Ling-Yi Tsai, a renowned expert in HRTech, is dedicated to transforming recruitment processes with advanced technology. With her extensive experience, Ling-Yi has shed light on current challenges faced by job seekers, particularly the questionable practice of employers requesting resignations before delivering offer letters. Our conversation today delves into the intricacies of this emerging issue and explores effective strategies to navigate

Trend Analysis: Overemployment in Remote Work

In today’s interconnected landscape, a peculiar yet rapidly expanding trend is emerging as individuals increasingly navigate between multiple remote jobs, leveraging technology to remain productive. The phenomenon, known as overemployment, sees professionals moonlighting with concurrent positions, transforming traditional work paradigms and stirring discourse on ethics, efficiency, and productivity. The Rise of Overemployment in Remote Work Charting the Growth of Overemployment

Chase and Amex Revamp Premium Cards Amid Market Shake-Up

In the ever-evolving landscape of the credit card industry, Chase and American Express (Amex) embark on a bold journey to redefine their premium offerings amidst a backdrop of significant market shifts. As economic volatility persists, these leading issuers are not merely reacting to change; they are strategically leveraging it to reinforce their dominance. By intensifying their focus on affluent consumers

Virtual Card Integration – Review

In today’s digital age, businesses face the ongoing challenge of managing corporate expenses efficiently and securely. With indirect expenditures making up about 20% of a corporation’s total spend, managing these numerous small transactions becomes critical. The collaboration between Mastercard and Pay4You introduces a compelling solution that revolutionizes how businesses handle these financial operations, emphasizing transparency, control, and efficiency. Unpacking Virtual

Can AI Social Share Buttons Transform SEO Strategy?

Picture this: A single click by a user prompts an AI chatbot to summarize a web page’s content, potentially enhancing that page’s visibility across digital landscapes. As artificial intelligence evolves, it not only processes information but influences how content is shared and retrieved. In this increasingly digital world, AI social share buttons are shifting the ways websites engage with their