Microsoft has issued a warning regarding a new wave of CACTUS ransomware attacks. These attacks utilize malvertising lures to introduce DanaBot as an initial access vector. The ransomware operator Storm-0216, also known as Twisted Spider or UNC2198, is actively involved in these DanaBot infections.


In addition, Microsoft has disclosed that CACTUS ransomware attacks are actively exploiting vulnerabilities in the Qlik Sense data analytics platform. Furthermore, a new strain of macOS ransomware called Turtle, written in the Go programming language and signed with an adhoc signature to bypass Gatekeeper protections, has been discovered.

These developments have significant implications for cybersecurity. Organizations should be aware of the CACTUS ransomware attacks and take necessary precautions to protect their systems. Mitigations should include patching vulnerabilities in the Qlik Sense data analytics platform and implementing strong security measures to prevent malvertising and malware infections. The discovery of the Turtle ransomware strain highlights the need for vigilance and proactive defense against evolving threats. Microsoft's warning serves as a reminder of the ongoing battle against ransomware and the importance of staying informed and prepared.