Cybercriminals behind Cactus ransomware perform sophisticated attacks to steal corporate data

Cactus ransomware operation first appeared in the cybersecurity scene in March 2023. An increasingly complex campaign of cyberattacks has targeted businesses, resulting in multiple breaches. The perpetrators of the Cactus ransomware employ a series of calculated actions to breach corporate networks and obtain confidential information.
First, the offenders get access to business networks. This access is frequently obtained by a number of strategies, such as buying credentials that have been stolen, joining forces with malware distributors, initiating phishing campaigns, or taking advantage of network weaknesses. Once inside, these threat actors move methodically, frequently going unnoticed, around the network while they steal vital company information from servers.
After stealing the data, the attackers gain administrative rights on the network to further increase their level of control. At this point, the ransomware portion of their operation is carried out, encrypting files and leaving ransom notes on compromised systems.
The Cactus ransomware campaign is noteworthy for its use of double-extortion techniques. In order to obtain a decryption tool and restore access to their encrypted files, victims are forced to pay a ransom. In addition, if the ransom is paid, the attackers guarantee to delete any stolen material and to keep it a secret. When victims don't cooperate, the stolen information is made available to the public via Cactus' data leak website.
Over 80 companies are listed on Cactus' data leak site as of the most recent reports. These are organizations whose data has either been made available to the public or is in danger of being released, provided the ransom is not paid. This operation is a prime example of how attacks by ransomware have become more complex and effective in modern times.
| Name | Cactus ransomware |
| Traits | Data encryption, money extortion, threat of releasing sensitive corporate information |
| Infection means | Online advertisements, stolen credentials, software vulnerabilities |
| Ransom note | cAcTuS.readme.txt (can vary) |
| Extension added | .CTS1 (can vary) |
| Contact | cactus787835@proton.me (can vary) |
| Removal | Employing powerful removal tools such as SpyHunterCombo Cleaner |
| Remediation | Upon installation, malware can cause severe damage to system files, resulting in instability issues such as crashes and errors. However, FortectIntego PC repair can automatically fix any such damage |
The recent attack on Schneider Electric
Earlier this month, Schneider Electric, a leading French multinational corporation, experienced a ransomware attack targeting its Sustainability Business division. This division is known for its Resource Advisory product, a tool used for visualizing sustainability data, along with other specialized systems within the division.
The attack, confirmed by Schneider Electric, led to unauthorized access to data. The company's Global Incident Response team was promptly activated to manage and contain the situation. Efforts were focused on reinforcing the existing security measures and communicating with affected customers.
Schneider Electric's Sustainability Business division is undergoing comprehensive remediation to secure and restore its business platforms. This includes thorough testing of the operational capabilities of the systems affected by the ransomware attack. The company anticipates resuming normal access and functionality within the next couple of business days. The company said in the press release:[1]
Schneider Electric Global Incident Response team has been immediately mobilized to respond to the attack, contain the incident, and to reinforce existing security measures. Sustainability Business division has informed impacted customers
It's important to note that the Sustainability Business division operates independently on a separate network infrastructure, ensuring that no other divisions of Schneider Electric were compromised in this incident. The company has engaged external cybersecurity experts to conduct a detailed investigation of the breach.
Schneider Electric, which reported over $37 billion in revenue in 2022, has not officially commented on whether the Cactus ransomware group was responsible for this specific attack, which occurred on January 17. The incident underscores the ongoing challenges faced by multinational corporations in safeguarding their digital infrastructure against sophisticated cyber threats.
Cactus ransomware attack examples
There are numerous versions of Cactus ransomware that could be targeting various organizations. Below we will provide an example of what one of such attacks might look like.
Cactus is a type of ransomware that targets and encrypts files, changing their extensions to “.CTS1”. For example, a file originally named “1.jpg” would be renamed to “1.jpg.CTS1”, and similarly for other file types. This ransomware is characterized by its unique extension appending method, which can vary depending on the encryption mode used. In some cases, files may end up with double extensions, such as “.CTS1.CTS6”.
Upon successful encryption of data, Cactus leaves a ransom note titled “cAcTuS.readme.txt” in the affected system. This note informs the victims about the encryption of their systems and provides instructions for contacting the attackers to negotiate file recovery and prevent data leakage. The primary mode of contact suggested in the ransom note is through email, specifically at cactus787835@proton.me. Additionally, the note provides a backup communication channel via Tox chat, a secure messaging platform.
The content of the ransom note typically reads as follows:
Your systems were accessed and encrypted by Cactus.
To recover your files and prevent data disclosure contact us via email: cactus787835@proton.me
Your unique ID reference: –
Backup contact TOX (hxxps://tox.chat/):
[ID]
Beyond encryption, Cactus ransomware exhibits behaviors typical of contemporary cybercriminal tactics, such as data exfiltration. The attackers use the Rclone tool to transfer stolen files directly to cloud storage services. Following the data theft, a PowerShell script TotalExec is employed.
This script, often associated with the BlackBasta ransomware, facilitates the automated deployment of the encryption process across the compromised systems. This combination of data theft and encryption underscores the multifaceted threat posed by Cactus ransomware in cybersecurity incidents.
How to contain and remove the infection? Possible decryption solutions
Cactus ransomware can be effectively removed using advanced anti-malware solutions such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. However, before initiating the removal process, it's crucial to isolate the infection, which requires disconnecting all infected PCs from the network. Such isolation prevents the spread of ransomware to other systems and limits the malware's communication with any external control servers.
Once the infected systems are isolated, the next step is to initiate the removal process in Safe Mode. Safe Mode in Windows is a diagnostic mode that starts the system with a minimal set of drivers and services. Running anti-malware tools in Safe Mode enhances their effectiveness, as the ransomware is less likely to be active and thus can be more easily detected and removed.
After the ransomware has been successfully removed, the focus shifts to the recovery of encrypted files. While it's often challenging to decrypt files without the original encryption key, using data restore software offers the possibility of retrieving some lost data. These software tools can scan the affected drives and attempt to recover files that were encrypted by the ransomware.
Following the removal of the ransomware and attempts at data recovery, it's essential to address any potential system corruption. Windows systems, after a ransomware attack, may suffer from various issues like corrupted files or disrupted system settings. Utilizing a Windows repair tool, such as FortectIntego, can help in fixing these corruptions, and restoring system stability and functionality.
In addition to these steps, there are also additional tips and best practices for dealing with ransomware attacks. These tips cover a range of strategies from preventive measures to limit the risk of infection to post-attack protocols that help in mitigating the damage and preventing future incidents. By following these comprehensive guidelines, users and administrators can enhance their resilience against ransomware threats and safeguard their data and systems more effectively.
Was this guide helpful?
Be the first to comment