logo

Emulating the Prickly Cactus Ransomware

ID: 264ab933-e420-5158-a9b7-9b4ca4713bf3

STIX ID: report--264ab933-e420-5158-a9b7-9b4ca4713bf3

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2024-07-25

Date Updated: 2026-04-22

Author: Francis Guibernau

...
...

This report documents the Cactus ransomware campaign (active since March 2023) and provides an AttackIQ assessment template to emulate its attack chain: exploitation of external VPNs for initial access, persistence via scheduled tasks and RunOnce registry keys, SSH-based C2, payload staging with PowerShell, discovery and deletion of shadow copies, and file encryption combined with data exfiltration (double extortion using RSA-2096 and AES-256-CBC). It maps observed behaviors to MITRE ATT&CK techniques, describes detection signatures and mitigations, and recommends emulation scenarios (including lateral movement via PAExec) to validate and improve defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.