Cybersecurity researchers have shed light on a new ransomware strain dubbed CACTUS, which was found to exploit known vulnerabilities in VPN devices in order to gain initial access to targeted networks.
See also: CERT-UA warns of SmokeLoader and RoarBAT malware attacks against Ukraine

“Once inside the network, CACTUS actors attempt to enumerate local and network user accounts, in addition to accessible ones, before creating new user accounts and leveraging custom scripts to automate the deployment and firing of the ransomware encryptor via scheduled tasks,” Kroll says in a report shared with The Hacker News.
See also: FBI: “Shuts down” domains linked to DDoS-for-hire services
Ransomware has been observed targeting large commercial entities since March 2021, with attacks using double-blackmail tactics to steal sensitive data before encryption. To date, no data leak locations have been identified.
After a successful exploitation of vulnerable VPN devices, an SSH backdoor is created to maintain permanent access and a series of PowerShell commands are executed to conduct a network scan and identify a list of machines to encrypt.
CACTUS attacks also use Cobalt Strike and a tool referred to as Chisel for command and control, along with remote monitoring and management (RMM) software, such as AnyDesk, to push files to infected computers.
See also: Microsoft: Iranian hacking groups involved in ongoing Papercut attacks
Steps have also been taken to disable and uninstall security solutions, as well as extract credentials from web browsers and the Local Security Authority Subsystem Service (LSASS) for privilege escalation purposes.
Privilege escalation is followed by lateral movement, data leakage, and ransomware deployment. The latter is achieved through a PowerShell script, which has also been used by Black Basta.
A new aspect of CACTUS is the use of a batch script to extract the ransomware binary using 7-Zip, followed by extracting the .7z file before executing the payload.
“CACTUS essentially encrypts itself, making it harder to detect and helping it evade antivirus tools and network monitoring,” Laurie Iacono, deputy chief cybersecurity officer at Kroll, told The Hacker News.
“This new ransomware named CACTUS exploits a vulnerability in a popular VPN appliance, showing that threat actors continue to target remote access and unpatched vulnerabilities for initial access.”
This development comes a few days after Trend Micro shed light on another type of ransomware, known as Rapture, which has some similarities to other families such as Paradise.
“The entire infection chain takes three to five days at most,” the company said, with initial recognition followed by the deployment of Cobalt Strike, which is then used to drop the .NET-based ransomware.

The intrusion is believed to have been facilitated through vulnerable websites and publicly accessible servers, making it imperative that companies take steps to keep their systems up to date and implement the principle of least privilege (PoLP).
"Although its operators use tools and resources that are readily available, they have managed to use them in a way that enhances Rapture's capabilities by making it more stealthy and more difficult to analyze," Trend Micro said.
CACTUS and Rapture are the latest additions to a long list of new ransomware families that have come to light in recent weeks, including Gazprom, BlackBit, UNIZA, Akira, and a variant of the NoCry ransomware called Kadavro Vector.
Information source: thehackernews.com
