Cactus Ransomware

What is CACTUS Ransomware?

CACTUS ransomware is a sophisticated, double-extortion ransomware strain that targets corporate networks, primarily exploiting vulnerabilities in virtual private network (VPN) appliances to gain initial access. CACTUS was first identified in early 2023 and designed to infiltrate, persist, and propagate within large enterprise networks, where it encrypts sensitive data and infiltrates it for added ransom leverage.

CACTUS RANSOMWARE METHODOLOGY

The Cactus ransomware’s advanced methodologies highlight how ransomware has evolved to become one of the most resilient threats in cybersecurity. Its structure includes multi-layered encryption, double extortion tactics, and a wide range of lateral movement and persistence techniques. Here’s the Cactus ransomware attack strategy and methods:

  • Double Extortion Ransomware
    Cactus ransomware not only encrypts victim files but also threatens data leakage if the ransom remains unpaid, a tactic aimed at increasing the pressure on victims. This adds a dimension to the attack that doubles the risk for organizations, impacting both data availability and confidentiality.
  • Exploiting VPN Vulnerabilities
    The ransomware primarily leverages vulnerabilities in VPN software (specifically targeting Fortinet, with CVE-2023-38035) to gain entry, a common attack vector in supply chain attacks. By exploiting this public-facing application vulnerability (MITRE ATT&CK T1190), attackers bypass traditional network defenses and gain access to internal systems.
  • Persistence via SSH Backdoors and Scheduled Tasks
    Once inside, Cactus establishes persistent access by setting up SSH backdoors and utilizing scheduled tasks (T1053) to maintain continuous control over the system. This helps attackers to reinforce their presence even after reboots or security updates, allowing them to deliver additional payloads.
  • Network Discovery and Credential Dumping
    Cactus performs thorough network reconnaissance to map all IP addresses, user accounts, and system connections using tools like SoftPerfect and PSNmap (MITRE T1078, T1087, T1049). For lateral movement, it uses credential-harvesting techniques, such as LSASS dumping and browser data extraction, to escalate privileges and move laterally within the network (T1555, T1003).
  • C2 Communication and Lateral Movement
    Cactus employs tools such as AnyDesk and Splashtop for RMM (Remote Monitoring and Management) to maintain access, while Chisel and Cobalt Strike facilitate covert C2 communication through proxy channels, evading detection (T1219, T1090).
  • Exfiltration and File Encryption Process
    With tools like RClone for cloud-based data exfiltration (T1567.002), Cactus efficiently extracts sensitive information from victim systems. Following exfiltration, Cactus uses AES-256 (CBC mode) combined with RSA-4096 for file encryption, partially encrypting files larger than 7.7 MB for efficiency. Encryption concludes with the addition of unique file extensions and the injection of ransom notes into every folder processed.
  • Disabling Security and Backup Mechanisms
    The ransomware neutralizes defenses by uninstalling antivirus software, disabling backup services, and deleting shadow copies, which prevents recovery efforts (T1562.001). It also monitors for and terminates specific processes (e.g., SQL, backup, antivirus), effectively disrupting critical services and ensuring the encryption process remains uninterrupted.
  • Unique Technical Aspects
    The payload behavior is heavily parameter-dependent, where arguments like -r and -s dictate execution flow. For instance, the -r argument initiates persistence through scheduled tasks. Cactus also generates mutexes to prevent multiple instances of encryption, and the ransomware’s handling of encryption keys (converting hex data into RSA keys) reflects a sophisticated use of cryptographic standards.

The CACTUS ransomware exemplifies a sophisticated form of double-extortion ransomware, targeting corporate networks by exploiting VPN software vulnerabilities, specifically known CVEs in popular appliances like Fortinet VPNs. Once inside the target environment, it creates a command and control (C2) pathway through SSH, establishing persistence via scheduled tasks and making lateral movement easier within the compromised network.

Picture 1.png 13 55 58 099

Key Features and Techniques of CACTUS Ransomware

  • Encryption of Ransomware Binary:
    CACTUS stands out due to its advanced obfuscation techniques. The ransomware encrypts its binary using a batch script and 7-Zip to download and extract the encryptor binary. After extraction, it uses a specific flag to execute the binary, then deletes the ZIP archive. This process minimizes detection by antivirus and monitoring tools.

  • Persistence via Scheduled Tasks and SSH Backdoor:
    Once inside a network, CACTUS ransomware maintains its foothold through scheduled tasks that launch an SSH backdoor, enabling continuous control and persistence across reboots.

  • Network Scanning and Lateral Movement:
    The ransomware employs tools like SoftPerfect Network Scanner (netscan) and PowerShell commands for endpoint enumeration. It uses a modified version of PSnmap to map out devices within the compromised network, allowing the threat actors to prioritize high-value targets. User account discovery relies on successful login entries in the Windows Event Viewer.

  • Leveraging Legitimate Tools and Cobalt Strike:
    CACTUS uses a suite of legitimate remote access tools like Splashtop, AnyDesk, and SuperOps RMM for stealthy access. For post-exploitation activities, it utilizes Cobalt Strike—a penetration testing tool widely exploited in malicious campaigns—and Chisel, a proxy tool, to mask communications.

  • Privilege Escalation and AV Disabling:
    CACTUS escalates privileges on infected devices, using batch scripts to uninstall popular antivirus solutions, effectively disabling defenses and increasing attack success.

  • Data Exfiltration and Automated Encryption Deployment:
    Using the Rclone tool, CACTUS exfiltrates data to cloud storage. It then automates the encryption process with a PowerShell script, TotalExec, which has previously been linked to the BlackBasta ransomware group. This script enables rapid and widespread encryption, increasing leverage for ransom demands.

How CACTUS Ransomware Operates

  • Entry and C2 Establishment: By exploiting unpatched VPN vulnerabilities, CACTUS gains access, then establishes C2 through SSH and scheduled tasks for persistent footholds.
  • Network Mapping and Credential Harvesting: The ransomware scans the network to identify potential devices for infection. It employs tools to collect credentials from browser storage and the LSASS process, which are essential for accessing additional devices and advancing through the network.
  • Antivirus Evasion and Encryption: Using msiexec, CACTUS uninstalls common antivirus solutions, aiming to avoid detection. The ransomware itself is encrypted with an AES key, requiring decryption for full payload analysis—a tactic that complicates investigation and enables it to bypass certain defenses.
  • Data Exfiltration and Encryption: Using RSA and AES encryption, CACTUS encrypts files on compromised systems and exfiltrates sensitive data through tools like Rclone, storing it in cloud repositories. The ransomware then drops a ransom note, demanding payment for data decryption and promising exposure if demands aren’t met.

Key Targets

Primarily, CACTUS has focused on larger organizations with vulnerable VPN infrastructure that could feasibly meet significant ransom payments, a pattern aligned with its high-stakes demands.

How to reduce risk?

  • Patch VPN Vulnerabilities: Addressing known flaws in VPN software is critical, as these are a primary access vector.
  • Implement Endpoint Monitoring: Employ behavioral analysis tools capable of detecting anomalous PowerShell and network scanning activities.
  • Use Strong Multi-Factor Authentication: Reinforcing user authentication protocols makes lateral movement more challenging for attackers.
  • Network Segmentation: Isolating critical assets helps prevent lateral movement within the network.
  • Network Security and Monitoring: Continuous monitoring helps detect unauthorized scanning and abnormal access attempts.
  • Anti-Ransomware Solutions: Solutions like Check Point’s Harmony Endpoint focus on early threat identification to prevent data encryption and exfiltration.

CACTUS ransomware targets critical vulnerabilities, that’s why it is necessary to protect your business from these advanced threats, which is more powerful than before.

Secnora offers a comprehensive approach to ransomware protection, covering every phase from prevention to recovery, all within a budget-friendly framework. Our experts are equipped with top-tier tools, continuous support, and proactive monitoring to fortify your defenses and protect your sensitive data.