Zscaler discovers new RedEnergy Stealer-as-a-Ransomware campaign

Teilen:

The Zscaler ThreatLabz security team has issued a warning about a new malware variant called RedEnergy Stealer, which has been categorized as a hybrid Stealer-as-a-Ransomware (SaaR) threat. This new malware category combines data theft with encryption, allowing it to inflict maximum damage on the victim. The new stealer uses a fake browser update campaign to target vertical industries such as utilities, oil and gas, and telecommunications providers. The malware has the ability to steal information from different browsers and is therefore able to extract sensitive data. Additionally, the stealer includes various modules for performing ransomware activities. Attacked companies face the loss of sensitive data,

The stealer variant studied by ThreatLabZ analysts uses a deceptive Fake Updates campaign to trick people in targeted companies into updating their browsers. The redirection technique is used for this. When trying to access a company website via their LinkedIn profile, unsuspecting users are redirected to a website with malicious code. There they are prompted to install an apparently legitimate browser update using four different browser icons. Instead of a real update, however, the RedEnergy Stealer executable file is loaded onto your system.

zscaler redenergy saar infektionskette

The malware works in several stages and starts executing malicious files disguised as browser update hiding behind various popular browsers like Google Chrome, Microsoft Edge, Firefox or Opera. The attack is carried out superficially hidden behind a real certificate to inspire trust in the user. In the second phase, data is reloaded and persistence in the system is ensured. The malware installs four files on the victim’s system, two of which are executable and follow the same naming principle. Only one of the files carries the actual payload, which is loaded in the background while the other files mimic the browser update process. To ensure the desired persistence in the system, malicious,

Suspicious FTP interactions indicate possible data exfiltration and unauthorized file uploads. The malware contains ransomware modules that steal user data with the “.FACKOFF!” extension. encrypt them so that they are no longer accessible until a ransom is paid. It also modifies the desktop.ini file to bypass detection and change file system folder display settings. In the final phase, the malware deletes shadow drive data and Windows backup plans, thereby reinforcing ransomware characteristics. RedEnergy Stealer drops a batch file and ransom note on affected systems, demanding payment for decrypting the files.

Schlussfolgerung

The technical analysis of the malware has revealed its dual functionality as a stealer and ransomware and represents an alarming development compared to conventional attacks. The attack campaigns analyzed show the further development of attack methods and a specialization in different industries and organizations. These novel Stealer as a Ransomware campaigns underline the importance of robust security measures and the need to raise user awareness of novel attack patterns.

 

(c) Herbert Wieler

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:17 am, Juli 2, 2025
Wetter-Symbol 20°C
L: 18° | H: 21°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 79 %
Druck: 1014 mb
Wind: 6 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 34%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 21°°C 0.26 mm 26% 11 mph 80 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 12 mph 54 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 13 mph 95 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 17°°C 1 mm 100% 12 mph 91 % 1009 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 5 mph 79 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 75 % 1016 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 35 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 39 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,551.60
-1.46%
Ethereum(ETH)
€2,043.20
-3.18%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€1.85
-2.28%
Solana(SOL)
€125.20
-4.22%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134484
-3.87%
Shiba Inu(SHIB)
€0.000009
-1.58%
Pepe(PEPE)
€0.000008
-4.30%
Nach oben scrollen