Ransomware group profile · #28 by claimed victims
Cactus ransomware
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs
Victimology
Who Cactus claims to have breached, from 248 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| optiline.com optiline.com | Technology | EE | 21 Mar 2025 |
| fplfood.com fplfood.com | Agriculture and Food Production | US | 21 Mar 2025 |
| biagibros.com biagibros.com | Transportation | US | 21 Mar 2025 |
| assaabloy.com assaabloy.com | Manufacturing | SE | 17 Mar 2025 |
| kyb.com kyb.com | Technology | JP | 17 Mar 2025 |
| tempel.com tempel.com | Technology | US | 12 Mar 2025 |
| thermoid.com thermoid.com | Manufacturing | US | 12 Mar 2025 |
| baillie.com baillie.com | Financial Services | US | 12 Mar 2025 |
| urban1.com urban1.com | Technology | US | 12 Mar 2025 |
| rocketstores.com rocketstores.com | Retail & E-Commerce | US | 12 Mar 2025 |
| quigleyeye.com quigleyeye.com | Healthcare | US | 3 Mar 2025 |
| stanleyconsultants.com stanleyconsultants.com | Professional Services | US | 28 Feb 2025 |
All 248 Cactus victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Cactus is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Cactus ransomware still active?
How many victims has Cactus claimed?
Which industries does Cactus target?
Which countries are most affected by Cactus?
Where does VULONE get Cactus victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].