Microsoft warns of Cactus ransomware actors using malvertising to infect victims

siteadmin December 5, 2023

Hackers are using malware, distributed via online ads, to infect users with Cactus ransomware. The ransomware actor, referred to as Storm-0216, Twisted Spider and UNC2198, is now using the Danabot malware after previously collaborating with Qakbot. Danabot collects user data before making a handoff to Storm-0216. The Cactus ransomware poses a significant threat as it has antivirus detection techniques and has already victimized almost 70 individuals and entities.