https://thehackernews.com/2025/03/researchers-link-cactus-ransomware.html?m=0
Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates
Black Basta and CACTUS ransomware groups share the BackConnect module, suggesting a shift in affiliations.
cactus ransomwareblack bastaresearcherstacticsformer
https://securityaffairs.com/163506/data-breach/omnivision-data-breach.html
OmniVision disclosed a data breach after the 2023 Cactus ransomware attack
May 22, 2024 - The digital imaging products manufacturer OmniVision disclosed a data breach after the 2023 ransomware attack.
a dataafter thecactus ransomwareomnivisiondisclosed
https://www.helpnetsecurity.com/2023/12/01/qlik-sense-cactus-ransomware/
Qlik Sense flaws exploited in Cactus ransomware campaign - Help Net Security
Dec 1, 2023 - Attackers are exploiting three critical vulnerabilities in internet-facing Qlik Sense instances to deliver Cactus ransomware to target orgs.
qlik sensecactus ransomwareflawsexploited
https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html?version=meter+at+null
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
ToyMaker deploys LAGTOY malware to steal credentials and sell access to CACTUS ransomware groups for double extortion.
to sell
https://securityaffairs.com/155184/cyber-crime/danabot-spread-cactus-ransomware.html
Malvertising attacks rely on DanaBot to spread CACTUS Ransomware
Dec 4, 2023 - Microsoft warns of ongoing malvertising attacks using the DanaBot malware to deploy the CACTUS ransomware....
malvertisingattacksrelydanabotspread
https://www.trendmicro.com/tr_tr/research/25/b/black-basta-cactus-ransomware-backconnect.html
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal | Trend Micro (TR)
Mar 3, 2025 - In this blog entry, we discuss how the Black Basta and Cactus ransomware groups utilized the BackConnect malware to maintain persistent control and exfiltrate...
https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal | Trend Micro (US)
https://www.trendmicro.com/ko_kr/research/25/b/black-basta-cactus-ransomware-backconnect.html
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal | Trend Micro (KR)
Mar 3, 2025 - In this blog entry, we discuss how the Black Basta and Cactus ransomware groups utilized the BackConnect malware to maintain persistent control and exfiltrate...