Qlik Sense Exploited in Cactus Ransomware Campaign
ID: 152ec223-fcb5-585d-a50d-b5fddea58a14
STIX ID: report--152ec223-fcb5-585d-a50d-b5fddea58a14
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs observed a campaign exploiting public Qlik Sense vulnerabilities to achieve remote code execution and deploy Cactus ransomware; actors used the Qlik Sense Scheduler to launch PowerShell/BITS downloads of renamed ManageEngine UEMS, AnyDesk, and Plink, carried out discovery and persistence actions (including uninstalling Sophos and changing the administrator password), established RDP tunnels, and exfiltrated data with rclone — the report includes IPs, domains, file paths, and file hashes as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
