Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates

It has been discovered that threat actors using the CACTUS and Black Basta ransomware families depend on the same BackConnect (BC) module to sustain long-term control over compromised computers. This suggests that affiliates that were previously linked to Black Basta may have switched to CACTUS.

According to a Trend Micro research released on Monday, once it has been penetrated, it gives attackers extensive remote control capabilities that enable them to run instructions on the compromised system. This gives them the ability to steal private information, including bank data, personal files, and login credentials.

It is important to note that the BC module’s details were initially recorded in late January 2025. Because of overlaps with the QakBot loader, the cybersecurity business is tracking this module as QBACKCONNECT read more about Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *