Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors redransomware

Description

Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across IT, legal, hospitality, manufacturing, and education sectors predominantly in the US, using phishing and vulnerability exploitation with double-extortion tactics. Known victims: 16

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Red Ransomware (Red CryptoApp) is a medium-sophistication criminal threat actor group primarily targeting organizations for financial gain through ransomware attacks. They were first observed in early 2024, leveraging phishing and vulnerability exploitation with double-extortion tactics. Their activities include creating a 'Wall of Shame' data leak site to pressure victims into paying ransoms.

Goals & Targeting

Red Ransomware targets sectors with high-value data and operational continuity dependencies, such as legal and healthcare industries. Their victims are spread across multiple sectors, indicating a broad targeting approach focused on maximizing financial returns through extortion. The primary motivation is organizational-gain, achieved through ransom payments and the sale or exposure of stolen data.

Enhanced Description

Red Ransomware emerged in March 2024, debuting its operations with a series of attacks across multiple industries including IT, legal, hospitality, manufacturing, and education, predominantly targeting organizations in the United States. The group is known for employing double-extortion tactics, where victims are threatened with both data encryption and public exposure of sensitive information on their 'Wall of Shame' website. Red Ransomware's operations suggest a strategic approach to maximizing financial gain through targeted attacks that combine phishing campaigns with malicious macro-laced Office documents, vulnerability exploitation, and the deployment of custom ransomware.

Key Capabilities

  • Phishing campaigns using macro-laced Office documents
  • Vulnerability exploitation for initial access
  • Double-extortion tactics combining data encryption and leak threats
  • Establishment of a 'Wall of Shame' website to pressure victims
  • Ransomware deployment for financial gain

MITRE ATT&CK Tactics

Initial Access
Execution
Encryption
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1566.003 (Spear-phishing via email attachments)
T1486 (Valid accounts)
T1070 (Exploit public facing RPC service)
T1204 (Use of cryptocurrency)
T1092.001 (C2 over protocol)
T1059 (Lateral access via remote services)

Software / Tooling

Cobalt Strike
TeamViewer
RDP Hacking Tools
Custom Ransomware

Campaigns & Victims

Red Ransomware's campaigns have shown a focus on North American targets across various industries. Their operational model includes phases of reconnaissance, initial access via phishing or exploitation, lateral movement, data encryption, and victim shaming. Notable past operations include the compromise of at least 16 organizations, with ransoms demanded in cryptocurrency. The group's tactics suggest a possible affiliation with larger ransomware networks.

IOC Patterns

  • Spear-phishing emails containing malicious Office documents
  • C2 communication over standard protocols like HTTP/HTTPS
  • Encrypted files with specific extensions (.redransomware or similar)
  • Presence of data exfiltration tools prior to encryption
  • Deployment of custom ransomware binaries

Recommended Actions

  • Implement strict DMARC, SPF, and DKIM policies to reduce phishing success rates.
  • Block execution of macros in email attachments through software configuration.
  • Patch systems regularly to mitigate vulnerability exploitation risks.
  • Monitor for unusual outbound network traffic indicative of C2 communication.
  • Encrypt sensitive data with strong encryption and maintain offline backups.
  • Educate staff on recognizing suspicious emails and the risks of opening unknown attachments.

Suggested Tags

Ransomware
Double extortion
Financial gain
Criminal activity

Confidence Assessment

High confidence in Red Ransomware's operational model based on confirmed victims and campaign patterns. However, specific TTPs may evolve, and precise tooling used remains unclear from publicly available data.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Phishing
Double extortion
Financial gain
Criminal activity

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 5, 2024
Last Seen
Jun 11, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.