Cyber Threat Actor: Cactus
| Actor Type | Location | Known Incidents |
Criminal
|
France
|
5 incidents |
|---|
Profile
Cactus is a ransomware‑associated threat actor that operates under the alias Cactus and has been linked to operations originating from France. The group has demonstrated a pattern of targeting a variety of sectors including media conglomerates, business services providers, educational technology firms, logistics and retail companies, and industrial or energy enterprises. Geographically, its activity has been observed in North America and across Western Europe, affecting organizations in the United States, France, the Netherlands, Belgium, and Spain. Public attributions describe the actor’s primary motivation as financial gain, with incidents involving data theft followed by extortion threats and ransom demands, while some attacks have also caused service disruptions and temporary system isolations.
The actor’s tactics frequently begin with sophisticated social engineering or phishing lures designed to gain initial footholds within target networks. Once inside, Cactus employs aggressive scanning techniques to locate valuable assets and deploys heavily disguised malicious software to evade detection. The group’s tooling includes ransomware payloads that encrypt files and threaten to leak exfiltrated data unless payment is made, as well as malvertising campaigns that have been cited as a distribution method for its malware. Observed behaviors also involve data exfiltration of personal and corporate information, followed by notifications to victims offering credit monitoring or advising vigilance against further phishing attempts. No public sources link Cactus to a state sponsor or a larger criminal consortium; the actor is presented as an independent ransomware gang.
Representative operations attributed to Cactus include a 2025 breach of a major U.S. media conglomerate that compromised employee personal data through a social engineering attack, a 2024 ransomware incident affecting a Dutch educational materials provider that exposed personal details of hundreds of thousands of students and staff across several European countries, and a 2024 attack on the sustainability division of a French multinational energy company that resulted in the theft of terabytes of corporate data and threats to leak the information unless a ransom was paid. These examples illustrate the group’s focus on high‑profile entities, its reliance on deceptive access methods, and its consistent use of ransomware coupled with data‑leak extortion to achieve financial objectives.
