Security News > 2023 > November > Cactus ransomware exploiting Qlik Sense flaws to breach networks

Cactus ransomware exploiting Qlik Sense flaws to breach networks
2023-11-30 17:46

Cactus ransomware has been exploiting critical vulnerabilities in the Qlik Sense data analytics solution to get initial access on corporate networks.

In a recent report, cybersecurity company Arctic Wolf warns of Cactus ransomware actively exploiting these flaws on publicly-exposed Qlik Sense instances that remain unpatched.

The Cactus ransomware attacks that Arctic Wolf observed exploit the security issues to execute code that causes the Qlik Sense Scheduler service to initiate new processes.

In the final stage of the attack, the hackers deployed the Cactus ransomware on the breached systems.

The use of these tools and techniques are consistent with what researchers observed in previous Cactus ransomware attacks.

HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks.


News URL

https://www.bleepingcomputer.com/news/security/cactus-ransomware-exploiting-qlik-sense-flaws-to-breach-networks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Qlik 5 0 5 2 2 9