Netskope Threat Labs

Cactus

ATP Sandbox Adv. HeuristicsAV

Cactus is a ransomware operation that emerged in 2023 and featured in the mid 2023 ransomware threat landscape documented by Sekoia. Microsoft reported that DanaBot infections led to Cactus deployments, and Trend Micro later described shared backconnect infrastructure between the Cactus and Black Basta operations.

First seen
May 2023
Last seen
September 2026
Alert Name
Dump:Generic.Ransom.Cactus.A.FFFFFFFE
Generic.Ransom.Cactus.A.07C5C476
Generic.Ransom.Cactus.A.08B33260
Generic.Ransom.Cactus.A.0D63646E
Generic.Ransom.Cactus.A.105DE2B1
Generic.Ransom.Cactus.A.117B26C6
Generic.Ransom.Cactus.A.11F594B8
Generic.Ransom.Cactus.A.12BDC82F
Generic.Ransom.Cactus.A.136931BA
Generic.Ransom.Cactus.A.1399754D