Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, LookingFrog, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
RedACT operates with the primary objective of generating financial gain through ransomware deployments across a broad spectrum of sectors—including finance, defense, media, government, manufacturing, entertainment, critical infrastructure, legal services, non‑profits, IT and utilities. The group combines classic social engineering—such as spear‑phishing that hijacks legitimate email and social media accounts—with sophisticated cloud‑abuse tactics, including the use of compromised cloud storage buckets (Dropbox, OneDrive, AWS S3) for staging malware, uploading malicious payloads, and exfiltrating data. From a technical perspective, RedACT builds custom, metamorphic malware that includes droppers, backdoors, keyloggers and container‑based persistence mechanisms. They frequently deploy serverless cloud functions (e.g., Cloudflare Workers, AWS Lambda) to conceal command‑and‑control traffic and obfuscate attribution, while also tampering with legitimate third‑party web services to route botnet activity through stolen accounts or compromised infrastructure. Operationally, the group is known for conducting aggressive reconnaissance scans of victim IP blocks, discovering domain and local accounts via tools such as "net user" and "netsh", and maintaining a presence on endpoints through automated collection scripts and browser hijacking. RedACT’s campaigns have been observed against high‑profile victims like Hologic and FCCI Insurance Group but are likely to target any organisation that can offer lucrative payouts. In summary, RedACT presents a hybrid threat model that fuses human‑centric phishing with cloud‑native infrastructure exploitation, making it resilient against traditional perimeter defenses while continuously seeking new avenues for credential compromise and data exfiltration.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
RedACT is a medium‑sophistication criminal ransomware group that combines social engineering, compromised cloud resources and custom malware to execute financially motivated campaigns. Their operations leverage existing online personas and legitimate third‑party services for both phishing campaigns and covert command‑and‑control, resulting in exfiltration via cloud storage and occasional DDoS amplification through botnets.
Goals & Targeting
RedACT’s strategic objectives centre on maximizing financial return by compromising high‑value targets across diverse industries. The actor prioritises sectors that are budget‑tight yet potentially lucrative—such as healthcare, insurance, defense contractors, and critical utilities—and leverages insider or impersonated identities to lower detection risk. Attackers adopt a dual approach: initial spear‑phishing campaigns establish footholds, while subsequent lateral movement and persistence layers facilitate data exfiltration through cloud channels and ransomware deployment. By embedding malicious code in widely used cloud services, RedACT also seeks to extend its reach into third‑party ecosystems, broadening the attack surface for future operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedACT has executed at least two documented ransomware operations, targeting Hologic and FCCI Insurance Group, both sectors with significant financial resources and valuable data. Campaigns appear to follow a rapid lifecycle: initial reconnaissance and credential compromise via phishing or compromised accounts, followed by lateral movement using automated scripts and local account exploitation, culminating in ransomware deployment and exfiltration through cloud storage. The actor’s use of serverless functions and malicious images suggests an emphasis on obfuscation and low‑trace persistence, while botnet activity indicates a capacity for distributed denial‑of‑service amplification to pressure victims or cover infrastructure. Though the data set is limited, observed patterns imply opportunistic targeting across multiple industries rather than selective, long‑term persistence in individual organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level is moderate. Evidence comes from a limited number of documented incidents (two victims) and generic references to TTPs that are common among many threat actors, which constrains definitive attribution. The analysis relies heavily on reconstructed capabilities and tool lists rather than hard forensic artifacts, leaving gaps in the exact operational tempo, persistence mechanisms, and malware variants used. Further evidence—including sample binaries, threat actor signatures, or confirmed infrastructure—would strengthen conclusions.
No observed data linked yet.
45
Techniques
45
Tools
2
Campaigns
40
IOCs
0
Observed Data
13
Tactics