◇ SIGN IN
← all actors
ransomware

Cactus

activemedium confidence
Ransomware
Cactus
Attribution
RaaS / closed affiliate model (financially motivated, unattributed)
Origin
Unknown
First seen
2023
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
UAE
Sectors
Public sector, corporate (broad)

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE (Public sector, corporate (broad) sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Cactus is a ransomware operation first observed in March 2023, known for exploiting vulnerabilities in internet-facing appliances and for self-encrypting its payload to evade detection.

History

Cactus emerged in March 2023 and conducts double-extortion attacks. It is notable for gaining initial access through exploitation of vulnerabilities in public-facing appliances and remote-access products, and for using an encrypted/self-decrypting payload technique to hinder antivirus detection. Late in 2023 it ran a prominent campaign exploiting Qlik Sense vulnerabilities (CVE-2023-41265, CVE-2023-41266 and CVE-2023-48365), with researchers identifying thousands of exposed servers and scores of compromised hosts.

Cactus remained active through 2024-2025, listing victims on its leak site across manufacturing, professional services and other sectors, and has been associated in reporting with broader access-broker ecosystems.

Cactus's leak site has listed victims in the UAE among its international claims. Such listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2023
Qlik Sense exploitation campaign
Cactus exploited Qlik Sense vulnerabilities (ZeroQlik/DoubleQlik) to breach thousands of exposed servers.
2024
Continued double-extortion operations
Cactus continued listing victims via leak-site extortion across manufacturing and services.
2024
UAE leak-site listing
A UAE organization appeared on Cactus's leak site (claimed, not independently confirmed).

Claimed victims · 248 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
kyb.comJPTechnology
assaabloy.comSEManufacturing
urban1.comUSTechnology
quigleyeye.comUSHealthcare
rocketstores.comUSRetail & E-Commerce
lifting.comUSManufacturing
chfindustries.comUSManufacturing
This entry has been removed following a request from the company.USRetail & E-Commerce
bluedge.comUSTechnology
regulvar.comCAOther
britannicahome.comUSRetail & E-Commerce
thermoid.comUSManufacturing