• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft warns of malvertising scheme spreading cactus ransomware

Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware

You are here: Home / General Cyber Security News / Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware
December 4, 2023

Microsoft has warned of a new wave of CACTUS ransomware attacks that leverage malvertising lures to deploy DanaBot as an original access vector.

The DanaBot bacterial infections led to “hands-on-keyboard action by ransomware operator Storm-0216 (Twisted Spider, UNC2198), culminating in the deployment of CACTUS ransomware,” the Microsoft Risk Intelligence workforce explained in a collection of posts on X (formerly Twitter).

DanaBot, tracked by the tech giant as Storm-1044, is a multi-purposeful software together the lines of Emotet, TrickBot, QakBot, and IcedID which is able of performing as a stealer and a position of entry for following-stage payloads.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


UNC2198, for its aspect, has been earlier observed infecting endpoints with IcedID to deploy ransomware families these kinds of as Maze and Egregor, as detailed by Google-owned Mandiant in February 2021.

Cybersecurity

Per Microsoft, the danger actor has also taken edge of preliminary access supplied by QakBot infections. The transform to DanaBot is likely the end result of a coordinated law enforcement procedure in August 2023 that took down QakBot’s infrastructure.

“The recent Danabot campaign, first observed in November, appears to be utilizing a private variation of the data-thieving malware as a substitute of the malware-as-a-services offering,” Redmond even more pointed out.

The qualifications harvested by the malware are transmitted to an actor-controlled server, which is adopted by lateral movement by way of RDP indication-in makes an attempt and in the end handing off accessibility to Storm-0216.

The disclosure comes times soon after Arctic Wolf revealed yet another established of CACTUS ransomware attacks that are actively exploiting critical vulnerabilities in a details analytics system named Qlik Feeling to acquire accessibility to corporate networks.

It also follows the discovery of a new macOS ransomware strain dubbed Turtle that’s penned in the Go programming language and is signed with an adhoc signature, thereby stopping it from becoming executed upon launch because of to Gatekeeper protections.

Observed this short article appealing? Observe us on Twitter  and LinkedIn to study much more distinctive content we submit.


Some components of this report are sourced from:
thehackernews.com

Previous Post: «agent racoon backdoor targets organizations in middle east, africa, and Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.
Next Post: LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware Attacks logofail: uefi vulnerabilities expose devices to stealth malware attacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.