Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors redact

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, LookingFrog, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

RedACT operates with the primary objective of generating financial gain through ransomware deployments across a broad spectrum of sectors—including finance, defense, media, government, manufacturing, entertainment, critical infrastructure, legal services, non‑profits, IT and utilities. The group combines classic social engineering—such as spear‑phishing that hijacks legitimate email and social media accounts—with sophisticated cloud‑abuse tactics, including the use of compromised cloud storage buckets (Dropbox, OneDrive, AWS S3) for staging malware, uploading malicious payloads, and exfiltrating data. From a technical perspective, RedACT builds custom, metamorphic malware that includes droppers, backdoors, keyloggers and container‑based persistence mechanisms. They frequently deploy serverless cloud functions (e.g., Cloudflare Workers, AWS Lambda) to conceal command‑and‑control traffic and obfuscate attribution, while also tampering with legitimate third‑party web services to route botnet activity through stolen accounts or compromised infrastructure. Operationally, the group is known for conducting aggressive reconnaissance scans of victim IP blocks, discovering domain and local accounts via tools such as "net user" and "netsh", and maintaining a presence on endpoints through automated collection scripts and browser hijacking. RedACT’s campaigns have been observed against high‑profile victims like Hologic and FCCI Insurance Group but are likely to target any organisation that can offer lucrative payouts. In summary, RedACT presents a hybrid threat model that fuses human‑centric phishing with cloud‑native infrastructure exploitation, making it resilient against traditional perimeter defenses while continuously seeking new avenues for credential compromise and data exfiltration.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Defense
Media
Government
Manufacturing
Entertainment
Critical infrastructure
Legal services
Non profit
Information technology
Utilities

Targeted Countries / Regions

US
CN
RU
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 hour ago

Executive Summary

RedACT is a medium‑sophistication criminal ransomware group that combines social engineering, compromised cloud resources and custom malware to execute financially motivated campaigns. Their operations leverage existing online personas and legitimate third‑party services for both phishing campaigns and covert command‑and‑control, resulting in exfiltration via cloud storage and occasional DDoS amplification through botnets.

Goals & Targeting

RedACT’s strategic objectives centre on maximizing financial return by compromising high‑value targets across diverse industries. The actor prioritises sectors that are budget‑tight yet potentially lucrative—such as healthcare, insurance, defense contractors, and critical utilities—and leverages insider or impersonated identities to lower detection risk. Attackers adopt a dual approach: initial spear‑phishing campaigns establish footholds, while subsequent lateral movement and persistence layers facilitate data exfiltration through cloud channels and ransomware deployment. By embedding malicious code in widely used cloud services, RedACT also seeks to extend its reach into third‑party ecosystems, broadening the attack surface for future operations.

Enhanced Description

Key Capabilities

  • Local account discovery via net user commands
  • Active reconnaissance scanning of victim IP blocks and services
  • Compromise and use of existing online personas and accounts for trusted access
  • Phishing campaigns leveraging compromised email, social media, and cloud accounts
  • Use of cloud storage (Dropbox, OneDrive, AWS S3) for exfiltration and tool staging
  • Build and operate botnets for DDoS/attack coordination
  • Abuse legitimate third‑party web services and compromised accounts for C2 and phishing
  • Leverage serverless cloud infrastructure (Cloudflare Workers, AWS Lambda) to obscure attribution
  • Develop custom malware components: payloads, droppers, post‑compromise tools, backdoors, packers
  • Implant malicious images in cloud or container registries for persistence
  • Internal spearphishing leveraging stolen accounts and impersonation

MITRE ATT&CK Tactics

Discovery
Reconnaissance
Resource Development
Initial Access
Command and Control
Exfiltration

ATT&CK Techniques

T1087
T1087.001
T1098
T1134
T1531
T1548
T1583
T1595
T1650
T1557
T1071
T1010
T1560
T1123
T1119
T1020
T1197
T1547
T1037
T1217
T1185
T1110
T1612
T1115
T1651
T1671
T1580
T1538
T1526
T1619
T1059
T1092
T1586
T1498
T1041
T1071.001
T1566.001
T1078

Software / Tooling

BRICKSTORM
Royal
netsh
PsExec
Scheduled Tasks
PowerShell
Dark
Explorer
AnyDesk
BianLian
Hook
systemd
Custom Malware
DarkBit
Backdoor
Keyloggers
AppDomainManager
Group Policy
Microsoft OneDrive
Google Drive
Windows Command Shell
GitHub
BRICKSTORM backdoor
Cl0p ransomware
Cloudflare Workers
BITS
wmic
Remote Access Tools

Campaigns & Victims

RedACT has executed at least two documented ransomware operations, targeting Hologic and FCCI Insurance Group, both sectors with significant financial resources and valuable data. Campaigns appear to follow a rapid lifecycle: initial reconnaissance and credential compromise via phishing or compromised accounts, followed by lateral movement using automated scripts and local account exploitation, culminating in ransomware deployment and exfiltration through cloud storage. The actor’s use of serverless functions and malicious images suggests an emphasis on obfuscation and low‑trace persistence, while botnet activity indicates a capacity for distributed denial‑of‑service amplification to pressure victims or cover infrastructure. Though the data set is limited, observed patterns imply opportunistic targeting across multiple industries rather than selective, long‑term persistence in individual organizations.

IOC Patterns

  • Compromise of existing online personas and accounts
  • Use of compromised email accounts for phishing emails and domain acquisition
  • Leverage cloud storage services to exfiltrate data and upload malware
  • Compromised third‑party web service accounts used for command and control
  • Embedding malicious code via cloud provider images or container registries
  • Deployment of serverless functions (Cloudflare Workers, AWS Lambda) for covert C2

Recommended Actions

  • Implement multi‑factor authentication for all email, social media, and third‑party service accounts.
  • Monitor login activity across cloud services (OneDrive, Google Drive, AWS S3) for anomalous uploads or access patterns.
  • Enforce least privilege on cloud resources and restrict access to serverless functions and container registries.
  • Deploy endpoint detection and response tools that detect abnormal use of system utilities such as netsh, wmic, sc.exe, and net user, and identify botnet C2 traffic.
  • Apply advanced email security (antispam, DMARC, BIMI) to reduce spear‑phishing successes.
  • Audit and enforce stringent account privileges through group policy and lockout policies for local/domain users.
  • Regularly review and revoke unused or suspicious API tokens and cloud credentials.
  • Segment network zones and limit lateral movement capabilities.

Suggested Tags

Account Discovery
Active Scanning
account-compromise
cloud-services
social-engineering
phishing
exfiltration-to-cloud
botnet
distributed-denial-of-service
web-service-C2
cloud-abuse
internal-spearphishing
credential-stealing
ransomware
data-exfiltration
remote-access-tools

Confidence Assessment

The confidence level is moderate. Evidence comes from a limited number of documented incidents (two victims) and generic references to TTPs that are common among many threat actors, which constrains definitive attribution. The analysis relies heavily on reconstructed capabilities and tool lists rather than hard forensic artifacts, leaving gaps in the exact operational tempo, persistence mechanisms, and malware variants used. Further evidence—including sample binaries, threat actor signatures, or confirmed infrastructure—would strengthen conclusions.

ATT&CK Techniques

Privilege Escalation
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.trendmicro.com — Cited by web research for: Google Drive
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Royal

Intel Summary

45

Techniques

45

Tools

2

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Criminal
Ransomware
Healthcare Sector
Insurance Sector
Account Discovery
Active Scanning
account-compromise
cloud-services
social-engineering
phishing
exfiltration-to-cloud
botnet
distributed-denial-of-service
web-service-C2
cloud-abuse
internal-spearphishing
credential-stealing
ransomware
data-exfiltration
remote-access-tools

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jun 28, 2026
Last Seen
Jun 28, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.