Skip to main content
Insights

The Growing Threat of CACTUS Ransomware: How Black Basta’s Affiliates Are Adapting 2025

Table of Contents Understanding the Rising Threat of CACTUS Ransomware: How Former Black Basta Affiliates Are Evolving What is CACTUS Ransomware? The Role of Former Black Basta Affiliates in CACTUS Ransomware How Does CACTUS Ransomware Work? Key Takeaways and Cybersecurity Insights ConclusionUnderstanding the Rising Threat of CACTUS Ransomware: How Former Black Basta Affiliates Are Evolving […]

Shiva 5 min read Updated Mar 5, 2025
The Growing Threat of CACTUS Ransomware: How Black Basta’s Affiliates Are Adapting 2025
Cybersecurity 965 words
Technical article

Understanding the Rising Threat of CACTUS Ransomware: How Former Black Basta Affiliates Are Evolving

Ransomware attacks have become one of the most pervasive threats in the digital world, disrupting businesses, governments, and individuals alike. Among the latest emerging ransomware threats, CACTUS ransomware stands out, especially due to its connection with former Black Basta affiliates. This article delves into the CACTUS ransomware, how it operates, its ties to Black Basta, and the evolving tactics that are making it more dangerous than ever.

What is CACTUS Ransomware?

CACTUS ransomware is a malicious software that encrypts files and demands a ransom from the victim for the decryption key. It is part of a growing trend in the world of cybercrime, where threat actors develop increasingly sophisticated methods to breach networks and extract sensitive data. The CACTUS ransomware is known for its ability to infiltrate systems stealthily, exfiltrate data, and then encrypt critical files, leaving businesses with little choice but to pay the ransom or suffer severe data loss.

The Role of Former Black Basta Affiliates in CACTUS Ransomware

Recent cybersecurity reports have revealed that CACTUS ransomware shares striking similarities with the infamous Black Basta ransomware. The connection between the two groups can be traced back to their use of a common malicious tool called the BackConnect (BC) module. This module allows attackers to maintain remote control over infected systems, facilitating the execution of commands, data theft, and, ultimately, ransomware deployment.

In a recent analysis by Trend Micro, it was highlighted that members of the Black Basta group appear to have transitioned to the CACTUS ransomware gang. This shift in tactics has made CACTUS a growing concern for cybersecurity experts. By using tools that were once associated with Black Basta, the threat actors have successfully carried over their tactics to a new ransomware operation.

How Does CACTUS Ransomware Work?

The Initial Infection

Similar to its predecessor, Black Basta, CACTUS relies on sophisticated initial access methods to infiltrate networks. One of the primary entry points involves the use of email bombing tactics. In this strategy, attackers send a massive volume of emails to prospective victims, often posing as IT support or helpdesk personnel. These emails trick users into installing malicious software, such as Quick Assist, which is commonly used by attackers to remotely control the victim’s machine.

Once installed, the attackers sideload a DLL loader named REEDBED using legitimate Microsoft OneDrive software. This loader decrypts and activates the BC module, granting the attackers full control over the system.

Data Exfiltration and Lateral Movement

After gaining access, CACTUS ransomware operators use a variety of post-exploitation techniques to escalate their attack. These include lateral movement within the infected network, where attackers attempt to spread their access to other systems. Additionally, they begin exfiltrating sensitive data, which could include login credentials, financial information, and personal files. This data is often used for extortion or sold on the dark web.

How Does CACTUS Ransomware Work

Encryption and Ransom Demand

The final step in the CACTUS attack involves encrypting the victim’s files. This encryption process locks valuable data behind complex encryption algorithms. In return for the decryption key, attackers demand a ransom. However, recent reports have suggested that not all CACTUS attacks result in successful encryption, with some operations failing at this stage, possibly due to defensive measures implemented by the target.

The Convergence of Tactics: CACTUS and Black Basta

The connection between Black Basta and CACTUS ransomware is not just technical but also strategic. The use of similar tools, tactics, and procedures (TTPs) indicates that the two groups may share resources, techniques, and even infrastructure. For instance, both groups have been observed using the BackConnect module, which was first seen in Black Basta’s attacks and later found in CACTUS incidents.

Trend Micro’s findings show that the CACTUS group is also utilizing a PowerShell script called TotalExec, which automates the deployment of the ransomware. This tool streamlines the process of spreading the encryption payload across the victim’s network, amplifying the effectiveness of the attack.

The Role of QakBot in CACTUS Ransomware

Interestingly, the Black Basta group had previously relied on the QakBot malware to gain initial access to corporate networks. However, following a large-scale law enforcement operation that dismantled QakBot’s infrastructure, Black Basta adapted by shifting to new access methods, many of which have now been adopted by the CACTUS group.

This shift suggests a closer operational relationship between the two ransomware families, with the CACTUS group inheriting and adapting the tactics once used by Black Basta. This evolving relationship highlights the importance of understanding the changing landscape of ransomware operations.

Key Takeaways and Cybersecurity Insights

  1. Evolving Ransomware Tactics

The transition from Black Basta to CACTUS ransomware highlights the dynamic nature of cybercrime groups. As law enforcement and cybersecurity experts shut down certain operations, attackers quickly adapt, creating new methods of infiltration and data theft.

  1. Importance of Advanced Detection Tools

Given the sophisticated nature of CACTUS ransomware, it is crucial for businesses to implement advanced threat detection systems. These tools can identify suspicious activities, such as the use of Quick Assist for remote access or unusual email patterns indicative of phishing attacks.

  1. Proactive Cybersecurity Measures

Preventing ransomware attacks requires a proactive approach. Organizations should regularly update their systems, implement strong backup strategies, and educate employees about recognizing phishing attempts. Additionally, securing Remote Desktop Protocol (RDP) portals and VPN endpoints can help reduce the risk of initial access exploits.

Conclusion

The rise of CACTUS ransomware serves as a stark reminder of the ever-evolving nature of cyber threats. With its ties to Black Basta and the adoption of sophisticated attack techniques, CACTUS represents a significant risk to organizations worldwide. By understanding how these ransomware operations function and evolving their defenses accordingly, businesses can better protect themselves from future attacks.

Stay ahead of ransomware threats—learn how to protect your network now.

Questions answered

Frequently asked questions.

Answers connected directly to this article and its subject.

01 What is CACTUS ransomware?

CACTUS ransomware is a type of malicious software that encrypts a victim’s files and demands a ransom for the decryption key. It is closely related to Black Basta ransomware and shares similar tactics.

02 How does CACTUS ransomware infect systems?

CACTUS often uses phishing emails, posing as IT support, to trick users into installing malicious software. It also exploits remote access tools like Quick Assist.

03 What is the BackConnect module?

The BackConnect (BC) module is a malicious tool used by CACTUS and Black Basta ransomware groups to maintain remote control over infected systems and execute further malicious activities.

04 What should businesses do to protect against CACTUS ransomware?

Businesses should implement advanced threat detection systems, regularly update their software, and train employees on recognizing phishing attacks.

05 Are there any connections between CACTUS and other ransomware?

Yes, CACTUS ransomware shares several tactics with Black Basta, suggesting a strong operational link between the two groups.

Shiva
Written by

Shiva

Engineering context

Research is useful when it survives contact with the system.

Explore implementation work, production systems and case studies from FireXCore.