logo

Inside the Operations of Cactus: The Rise of a Stealth-Focused Ransomware Threat

ID: bd893c78-3c4c-5101-84ac-0d9fff62501f

STIX ID: report--bd893c78-3c4c-5101-84ac-0d9fff62501f

Feed Name: Brandefense Blog

Threat Score
88/100

Date Published: 2026-01-07

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

This report profiles the Cactus ransomware group, a financially motivated, highly automated and stealth-focused actor observed since 2023 exploiting unpatched VPN appliances to gain direct enterprise access, using Chisel for covert tunneling and Rclone for cloud exfiltration to carry out double-extortion campaigns against large organizations (100+ confirmed victims by early 2025); it details their persistence and C2 techniques, tooling, evolution, and provides prioritized defensive recommendations (patch VPNs, enforce MFA, monitor for Chisel/Rclone and ntuser.dat anomalies, harden remote management, and segment networks).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.