CACTUS Ransomware Abuses Vulnerabilities

ransomware

A recent CACTUS ransomware campaign has been detected exploiting newly revealed vulnerabilities in Qlik Sense, a cloud analytics and business intelligence platform. Researchers from Arctic Wolf, including Stefan Hostetler, Markus Neis, and Kyle Pagelow, have identified this as the first documented case where threat actors using CACTUS ransomware have leveraged vulnerabilities in Qlik Sense for initial access.

Vulnerabilities exploited by CACTUS

The cybersecurity firm, responding to multiple instances of exploitation, highlighted three vulnerabilities disclosed over the past three months:

CVE-2023-41265 (CVSS score: 9.9) - An HTTP Request Tunneling vulnerability allowing a remote attacker to elevate privileges and execute requests on the backend server hosting the repository application.

CVE-2023-41266 (CVSS score: 6.5) - A path traversal vulnerability enabling an unauthenticated remote attacker to send unauthorized HTTP requests to specific endpoints.

CVE-2023-48365 (CVSS score: 9.9) - An unauthenticated remote code execution vulnerability resulting from improper validation of HTTP headers, enabling attackers to elevate privileges through tunneling HTTP requests.

Notably, CVE-2023-48365 stems from an incomplete patch for CVE-2023-41265, both disclosed by Praetorian in late August 2023. A fix for CVE-2023-48365 was released on September 20, 2023.

Arctic Wolf's observations indicate that successful exploitation of these flaws leads to the manipulation of the Qlik Sense Scheduler service. This is used to spawn processes that download additional tools, aiming to establish persistence and enable remote control.

These tools include ManageEngine Unified Endpoint Management and Security (UEMS), AnyDesk, and Plink. Threat actors have also been observed uninstalling Sophos software, changing the administrator account password, and creating an RDP tunnel via Plink.

The attack sequence concludes with the deployment of CACTUS ransomware, with attackers employing rclone for data exfiltration.

December 1, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.