CACTUS is a ransomware group from March 2023 that encrypts files with a '.cts1' extension.
Analyst brief
CACTUS is a ransomware group that emerged around March 2023. Target selection is not fully understood, but they focus on exploiting vulnerabilities for initial access. Key TTPs include encrypting files with the '.cts1' extension, dropping a 'cAcTuS.readme.txt' ransom note, conducting data exfiltration, and using the Tox service for victim extortion. Defenders should focus on strict vulnerability management, monitoring for anomalous file extensions ('.cts1'), and inspecting network traffic for Tox usage to align with these TTPs.
cactus
crime
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs