HomeSecurityRedEnergy: Stealer-as-a-Ransomware Targeting Energy and Telecommunications Sectors

RedEnergy: Stealer-as-a-Ransomware targeting energy and telecommunications sectors

“RedEnergy Stealer-as-a-Ransomware”, a Ransomware threat targeting the energy and telecommunications sectors

RedEnergy

An advanced ransomware threat named RedEnergy has been identified, targeting utility companies in the energy, oil, natural gas, telecommunications, and equipment sectors in Brazil and the Philippines via their LinkedIn pages.

The malware “has the ability to steal information from various browsers, allowing the isolation of sensitive data, and also incorporates various modules for executing ransomware activities”, said Zscaler researchers Shatak Jain and Gurkirat Singh in a recent analysis.

The researchers noted that the goal is to combine data theft with encryption to cause maximum damage to victims.

The starting point for the multi-stage attack is a FakeUpdates campaign (also known as SocGholish) that tricks users into downloading JavaScript- based malware under the guise of web browser updates

What makes it original is the use of trusted LinkedIn pages to target victims, redirecting users who click on the website URLs to a fake landing page that prompts them to update their browsers by clicking on the appropriate icon (Google Chrome, Microsoft Edge, Mozilla Firefox, or Opera) - this results in the download of a malicious executable file.

After a successful breach, the malicious binary file is used as a conduit to set up persistence, execute the actual browser update, and drop a stealer that can silently collect sensitive information and encrypt the stolen files. Victims are at risk of potential data loss, exposure or even the sale of their valuable data.

Zscaler said it discovered suspicious interactions that took place via an FTP (File Transfer Protocol) connection, a fact that increases the likelihood that valuable data is being transferred to infrastructures controlled by authorities.

RedEnergy: Stealer-as-a-Ransomware targeting energy and telecommunications sectors

In the final stage, RedEnergy's ransomware component proceeds to encrypt the user's data, adding the “.FACKOFF!” extension to each encrypted file, deleting existing backups and dropping a ransom note in each folder.

Victims are expected to pay 0.005 BTC (approximately $151) to a cryptocurrency wallet listed in the note in order to regain access to files. RedEnergy’s dual functions as a thief and ransomware represent an evolution of the cybercrime landscape.

The evolution also follows the emergence of a new category of threats RAT-as-a-Ransomware, in which remote access trojans (such as Venom RAT and Anarchy Panel RAT) have been equipped with ransomware modules to lock various file extensions behind encryption barriers.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS