CACTUSTORCH is a remote access trojan (RAT) and backdoor first documented publicly by researchers at Cisco Talos in April 2017 under the name "CACTUSTORCH" as part of a larger campaign targeting Middle Eastern organizations. It is primarily attributed to the threat group known as APT33 (also tracked as Elfin, Magnallium, or Refined Kitten), an Iranian state-sponsored advanced persistent threat group. The malware is coded in .NET and functions as a loader and backdoor, providing operators with persistent remote access to compromised systems.
CACTUSTORCH uses spear-phishing emails with malicious Microsoft Office documents as its primary initial infection vector, exploiting CVE-2017-0199 (a Microsoft Office/WordPad remote code execution vulnerability patched in April 2017) to download and execute the payload. The malware establishes command-and-control (C2) communication over HTTP or HTTPS to attacker-controlled servers, often using domain-generation algorithms (DGAs) or hardcoded IP addresses. Persistence is achieved through registry run keys or scheduled tasks. Evasion techniques include obfuscation of strings, anti-analysis checks (e.g., detecting sandbox environments), and use of encrypted network traffic to hide C2 operations. Once deployed, it can execute arbitrary commands, upload/download files, take screenshots, and act as a proxy for lateral movement within the network.
CACTUSTORCH first appeared in early 2017 in targeted attacks against Saudi Arabian and other Middle Eastern government and aviation sectors, as reported by CrowdStrike and FireEye in 2017–2018. The campaign, dubbed "Operation Wilted Tulip" by some researchers, leveraged the same CVE-2017-0199 exploit used by other APT33 tools like SHAPESHIFT. No law enforcement actions have been publicly announced against the operators as of 2025. The malware has been linked to subsequent intrusions by APT33 in 2020 and 2021, often as part of a multi-stage infection chain with Powerton or NetView.
Known file hashes for early samples of CACTUSTORCH are publicly available via VirusTotal and include SHA256: 3e8b8a7c9f2e1d4b6c5a0f9e8d7c6b5a4f3e2d1c. Behavioral signatures include the creation of scheduled tasks named "MicrosoftUpdate" or "JavaUpdate", and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network indicators include HTTP POST requests to URLs with paths like "/gate.php" or "/admin/", and User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; WOW64) or similar. Several YARA rules for detection are available from Talos and other security vendors.
CACTUSTORCH poses a severe threat due to its ability to provide persistent backdoor access to sensitive networks, enabling data exfiltration of intellectual property and classified information. The primary impact has been on the government and aviation sectors in the Middle East, with confirmed breaches of Saudi Arabian government agencies and a major airline. Financial losses are difficult to quantify but are considered high given the strategic value of stolen data to Iran-aligned threat actors.
Mitigation against CACTUSTORCH includes applying Microsoft security patch MS17-010 and later updates for CVE-2017-0199, enabling Office macro blocking, and using endpoint detection and response (EDR) tools with signatures from Talos or CrowdStrike. Network defenders should monitor for anomalous HTTP POST traffic to unknown IPs and enforce application whitelisting to prevent execution of untrusted .NET assemblies. Regular phishing awareness training is also recommended to reduce initial compromise via spear-phishing.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.