Cactus attacks Hornsyld Købmandsgaard
The Cactus Ransomware Gang's Attack on Hornsyld Købmandsgaard
The Cactus ransomware gang has attacked Hornsyld Købmandsgaard. Hornsyld Købmandsgaard is a Danish conglomerate that sells agricultural equipment, animal feed, fuel, provides construction services, runs grocery stores, and develops new animal feeds. It is made up of five companies and was founded in 1932. Its grocery arm is one of the few privately owned grocery stores in Denmark.
Cactus posted Hornsyld Købmandsgaard to its data leak site on September 5th but provided no further details. Cactus has been in operation since at least March 2023.
Method of Attack
Cactus has been observed employing known vulnerabilities within VPN appliances to initiate an initial breach. Once gaining entry to the network, Cactus operators engage in activities such as enumerating local and network user accounts and identifying accessible endpoints. They then proceed to generate new user accounts and utilize custom scripts for the automated rollout and activation of the ransomware encryptor through scheduled tasks.
Unique Characteristics of the Ransomware
It is noteworthy that the ransomware encryptor utilized by Cactus exhibits a unique characteristic – it necessitates a decryption key for the execution of the binary, likely implemented to evade detection by anti-virus software. This decryption key is concealed within a file containing random text named ntuser.dat, which is loaded through a scheduled task.
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!