Emulating the Prickly Cactus Ransomware
ID: 264ab933-e420-5158-a9b7-9b4ca4713bf3
STIX ID: report--264ab933-e420-5158-a9b7-9b4ca4713bf3
Feed Name: Security Boulevard
This report documents the Cactus ransomware campaign (active since March 2023) and provides an AttackIQ assessment template to emulate its attack chain: exploitation of external VPNs for initial access, persistence via scheduled tasks and RunOnce registry keys, SSH-based C2, payload staging with PowerShell, discovery and deletion of shadow copies, and file encryption combined with data exfiltration (double extortion using RSA-2096 and AES-256-CBC). It maps observed behaviors to MITRE ATT&CK techniques, describes detection signatures and mitigations, and recommends emulation scenarios (including lateral movement via PAExec) to validate and improve defensive controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
