logo

Qlik Sense Exploited in Cactus Ransomware Campaign

ID: 152ec223-fcb5-585d-a50d-b5fddea58a14

STIX ID: report--152ec223-fcb5-585d-a50d-b5fddea58a14

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2023-11-28

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs observed a campaign exploiting public Qlik Sense vulnerabilities to achieve remote code execution and deploy Cactus ransomware; actors used the Qlik Sense Scheduler to launch PowerShell/BITS downloads of renamed ManageEngine UEMS, AnyDesk, and Plink, carried out discovery and persistence actions (including uninstalling Sophos and changing the administrator password), established RDP tunnels, and exfiltrated data with rclone — the report includes IPs, domains, file paths, and file hashes as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.