Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates
It has been discovered that threat actors using the CACTUS and Black Basta ransomware families depend on the same BackConnect (BC) module to sustain long-term control over compromised computers. This suggests that affiliates that were previously linked to Black Basta may have switched to CACTUS.
According to a Trend Micro research released on Monday, once it has been penetrated, it gives attackers extensive remote control capabilities that enable them to run instructions on the compromised system. This gives them the ability to steal private information, including bank data, personal files, and login credentials.
It is important to note that the BC module's details were initially recorded in late January 2025. Because of overlaps with the QakBot loader, the cybersecurity business is...

