HomeSecurityCACTUS ransomware: Exploits Qlik Sense vulnerabilities

CACTUS ransomware: Exploits Qlik Sense vulnerabilities

A new CACTUS ransomware distribution campaign exploits security vulnerabilities recently disclosed in a cloud analytics and business intelligence platform called Qlik Sense .

CACTUS ransomware

“ This campaign marks the first documented case […] where threat deploying the CACTUS ransomware have exploited vulnerabilities in Qlik Sense for initial access actors ,” Arctic Wolf researchers Stefan Hostetler, Markus Neis, and Kyle Pagelow said .

The cybersecurity firm says the attacks likely exploit three vulnerabilities that have been disclosed in the last three months:

CVE-2023-41265 (CVSS score: 9.9): An HTTP Request Tunneling vulnerability that allows a remote attacker to elevate their privileges on the deviceand send requests that are executed by the backend server hosting the repository application.

CVE-2023-41266 (CVSS score: 6.5): This is a vulnerability that allows an unauthenticated remote attacker to transmit HTTP requests to unauthorized endpoints.

CVE-2023-48365 (CVSS Score: 9.9): Another critical vulnerability that allows unauthorized remote code execution.

See also: Black Basta ransomware: Gang has earned over $100 million through extortion

It is worth noting that the latest vulnerability is the result of an incomplete update for the first vulnerability CVE-2023-41265, which, along with CVE-2023-41266, was disclosed by Praetorian in late August 2023. A fix for CVE-2023-48365 was released on November 20, 2023.

In the new CACTUS ransomware attacks observed by Arctic Wolf, successful exploitation of vulnerabilities is followed by abuse of Scheduler . The goal is to create processes that allow the download of additional tools for creating persistence and setting up remote control.

Qlik Sense

This includes ManageEngine Unified Endpoint Management and Security (UEMS), AnyDesk, and Plink. Attackers can sometimes also uninstall Sophos software, change the password , and create an RDP tunnel through Plink.

See also: Qilin ransomware: Claims responsibility for attack on Yanfeng

The attack chains culminate with the deployment of the CACTUS ransomware, while the hackers also steal data.

The above shows that ransomware gangs are exploiting every means possible to infect devices and networks. However, there are some steps that businesses, organizations, and users can take to protect themselves.

One of the key steps in preventing ransomware attacks is to educate and inform users. Users should be aware of the latest threats and basic security principles in the digital space. This includes avoiding clicking on suspicious attachments or links, using strong passwords, and avoiding sharing sensitive data.

Another important step is to install up-to-date and reliable security software. Antivirus software and firewalls can detect and block malware before it can do any damage. You should also keep your operating system and applications up-to-date, as updates often include security fixes for known issues.

See also: Authorities arrest members of ransomware gang that attacked 71 countries

Finally, regularly backing up your important data is crucial to protecting yourself from ransomware. If your data is encrypted, you will be able to restore your original files from backups .These backups should be stored in a secure location, off the main system, to prevent them from being encrypted by ransomware.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS