Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across IT, legal, hospitality, manufacturing, and education sectors predominantly in the US, using phishing and vulnerability exploitation with double-extortion tactics. Known victims: 16
Objectives
Executive Summary
Red Ransomware (Red CryptoApp) is a medium-sophistication criminal threat actor group primarily targeting organizations for financial gain through ransomware attacks. They were first observed in early 2024, leveraging phishing and vulnerability exploitation with double-extortion tactics. Their activities include creating a 'Wall of Shame' data leak site to pressure victims into paying ransoms.
Goals & Targeting
Red Ransomware targets sectors with high-value data and operational continuity dependencies, such as legal and healthcare industries. Their victims are spread across multiple sectors, indicating a broad targeting approach focused on maximizing financial returns through extortion. The primary motivation is organizational-gain, achieved through ransom payments and the sale or exposure of stolen data.
Enhanced Description
Red Ransomware emerged in March 2024, debuting its operations with a series of attacks across multiple industries including IT, legal, hospitality, manufacturing, and education, predominantly targeting organizations in the United States. The group is known for employing double-extortion tactics, where victims are threatened with both data encryption and public exposure of sensitive information on their 'Wall of Shame' website. Red Ransomware's operations suggest a strategic approach to maximizing financial gain through targeted attacks that combine phishing campaigns with malicious macro-laced Office documents, vulnerability exploitation, and the deployment of custom ransomware.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Red Ransomware's campaigns have shown a focus on North American targets across various industries. Their operational model includes phases of reconnaissance, initial access via phishing or exploitation, lateral movement, data encryption, and victim shaming. Notable past operations include the compromise of at least 16 organizations, with ransoms demanded in cryptocurrency. The group's tactics suggest a possible affiliation with larger ransomware networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Red Ransomware's operational model based on confirmed victims and campaign patterns. However, specific TTPs may evolve, and precise tooling used remains unclear from publicly available data.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics