Zscaler discovers new RedEnergy Stealer-as-a-Ransomware campaign

Share:

The Zscaler ThreatLabz security team has issued a warning about a new malware variant called RedEnergy Stealer, which has been categorized as a hybrid Stealer-as-a-Ransomware (SaaR) threat. This new malware category combines data theft with encryption, allowing it to inflict maximum damage on the victim. The new stealer uses a fake browser update campaign to target vertical industries such as utilities, oil and gas, and telecommunications providers. The malware has the ability to steal information from different browsers and is therefore able to extract sensitive data. Additionally, the stealer includes various modules for performing ransomware activities. Attacked companies face the loss of sensitive data,

The stealer variant studied by ThreatLabZ analysts uses a deceptive Fake Updates campaign to trick people in targeted companies into updating their browsers. The redirection technique is used for this. When trying to access a company website via their LinkedIn profile, unsuspecting users are redirected to a website with malicious code. There they are prompted to install an apparently legitimate browser update using four different browser icons. Instead of a real update, however, the RedEnergy Stealer executable file is loaded onto your system.

zscaler redenergy saar infektionskette

The malware works in several stages and starts executing malicious files disguised as browser update hiding behind various popular browsers like Google Chrome, Microsoft Edge, Firefox or Opera. The attack is carried out superficially hidden behind a real certificate to inspire trust in the user. In the second phase, data is reloaded and persistence in the system is ensured. The malware installs four files on the victim’s system, two of which are executable and follow the same naming principle. Only one of the files carries the actual payload, which is loaded in the background while the other files mimic the browser update process. To ensure the desired persistence in the system, malicious,

Suspicious FTP interactions indicate possible data exfiltration and unauthorized file uploads. The malware contains ransomware modules that steal user data with the “.FACKOFF!” extension. encrypt them so that they are no longer accessible until a ransom is paid. It also modifies the desktop.ini file to bypass detection and change file system folder display settings. In the final phase, the malware deletes shadow drive data and Windows backup plans, thereby reinforcing ransomware characteristics. RedEnergy Stealer drops a batch file and ransom note on affected systems, demanding payment for decrypting the files.

Conclusion

The technical analysis of the malware has revealed its dual functionality as a stealer and ransomware and represents an alarming development compared to conventional attacks. The attack campaigns analyzed show the further development of attack methods and a specialization in different industries and organizations. These novel Stealer as a Ransomware campaigns underline the importance of robust security measures and the need to raise user awareness of novel attack patterns.

 

(c) Herbert Wieler

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:01 pm, Jul 1, 2025
weather icon 24°C
L: 22° | H: 25°
scattered clouds
Humidity: 66 %
Pressure: 1014 mb
Wind: 10 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 41%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:47 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
22° | 25°°C 0.38 mm 38% 11 mph 80 % 1022 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 22°°C 0 mm 0% 5 mph 68 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 20°°C 0 mm 0% 6 mph 75 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0.2 mm 20% 5 mph 80 % 1017 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,606.89
-1.29%
Ethereum(ETH)
€2,039.08
-3.26%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.85
-4.30%
Solana(SOL)
€124.13
-6.01%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134210
-4.44%
Shiba Inu(SHIB)
€0.000009
-2.28%
Pepe(PEPE)
€0.000008
-5.24%
Scroll to Top