#1 Trending Cybersecurity News & Magazine
Sunday, September 17, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Cactus Ransomware Group Hits 5 Global Corporations, Marfrig, Seymours Among Victims

The Cactus ransomware group flaunted their acquired assets, openly identifying their victims and providing brief descriptions of each on their dark web channel.

Ashish Khaitan by Ashish Khaitan
September 6, 2023
in Firewall Daily, Hacker Claims
0
Cactus Ransomware Group
629
SHARES
3.5k
VIEWS
Share on LinkedInShare on Twitter

In a concerning turn of events, a relatively new ransomware group known as the Cactus ransomware group has recently added five high-profile victims to their dark web leak site.

Victims from diverse regions around the globe and across a range of industries have become ensnared in the mysterious cyber threat’s intricate web.

You might also like

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

The Three Trends to Watch in the Growing Threat Landscape

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

The affected entities include Seymours, Groupe Promotrans, MINEMAN Systems, Maxxd Trailers, and Marfrig Global Foods.

The Cactus ransomware group promptly flaunted their acquired assets, openly identifying their victims and providing brief descriptions of each on their dark web channel.

Cactus ransomware group targets multiple firms 

Cactus ransomware group
Source: Twitter

The first on the list of victims is Seymours, a renowned Surrey estate agent with a strong presence in the region.

Seymours boasts six offices situated strategically in Ripley, Guildford, Burpham, Woking, and West Byfleet, with one dedicated to the management and letting of properties available for sale.

The second victim, Promotrans, operates within the Professional Training and coaching sector.

With a workforce ranging from 251 to 500 individuals and a revenue stream estimated at $25 million to $50 million, Promotrans is a prominent player in the industry.

The company is headquartered in the vibrant city of Paris, ÃŽle-de-France, France.

Cactus ransomware group
Source: Twitter

MAXXD Trailers, the following entity on the list, operates as a subsidiary of Maxey Trailers Mfg. Inc., a Texan company established in 1999.

Starting as a one-person operation, Maxey Trailers has grown substantially, employing 70 dedicated individuals responsible for producing a staggering 5,000 trailers annually. Their reach extends across the United States and Canada.

Marfrig Global Foods, another victim of the Cactus ransomware group, is the second largest Brazilian food processing company, after JBS and specializes in processing beef products.

Cactus ransomware group
Source: Twitter

The last victim mentioned, MINEMAN Systems, holds a crucial role in marketing concentrates and metals sourced from mining operations.

The Cyber Express reached out to the affected companies to obtain their official responses or statements regarding these cyber attacks.

However, at the time of writing, no official response had been received from these corporations, leaving the claims of the cyber attacks unverified.

Modus operandi of the Cactus ransomware group

The emergence of the Cactus ransomware group is nothing less than mysterious. This new threat actor has quickly gained notoriety in the dark web markets for its sophisticated tactics. 

The CACTUS cybercriminal group primarily focuses on VPN appliances for initial access and the installation of backdoors.

In their attacks thus far, they have exploited known vulnerabilities in VPN appliances, seamlessly maneuvering through various systems. 

The group’s name, ‘CACTUS,’ stems from the filename provided within their ransom note, ‘cAcTuS.readme.txt,’ and their self-declared moniker within the same note.

Encrypted files are marked with the extension ‘.cts1,’ although it is worth noting that the number at the end of the extension may vary across incidents and victims. 

CACTUS’s modus operandi involves gaining initial access to a VPN appliance using a service account, followed by deploying an SSH backdoor connected to their command-and-control (C2) server. This backdoor execution occurs via a scheduled task. 

Subsequently, the threat actors engage in a comprehensive network survey, employing a commercial Windows network scanner by an Australian company named SoftPerfect.

Further PowerShell commands and scripts are utilized to enumerate networked computers and extract user accounts from the Windows Security event log. 

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Cactus ransomware groupransomware groupThe Cyber ExpressThe Cyber Express News
Previous Post

G20 Cyber Attack Hacktivists Announce Plans to Target Indian Organizations Prior to G20 Summit

Next Post

Protect Clear Text Passwords From Exposure, Install Updates Warns CISA ICS Advisory

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

by Vishwa Pandagle
September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

by Editorial
September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

by Ashish Khaitan
September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

by Vishwa Pandagle
September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

by Editorial
September 16, 2023
Next Post
Vulnerabilities in ICS

Protect Clear Text Passwords From Exposure, Install Updates Warns CISA ICS Advisory

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

September 16, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance