Unmasking RedEnergy: The New Hybrid Threat in Cybersecurity
The innovative cybersecurity group, Zscaler ThreatLabz, recently discovered a new malware variant—RedEnergy Stealer—that redefines ransomware threats by adopting a dual role as a data stealer and ransomware. This groundbreaking discovery signals a significant shift in the landscape of cybersecurity threats.
Targeting a diverse range of industries—including energy utilities, oil, gas, telecom, and machinery—RedEnergy executes a phony update campaign, allowing it to infiltrate various browsers. It can thus stealthily extract sensitive data and perform ransomware activities simultaneously. The term RedEnergy Stealer was derived from common method names noticed during the analysis.
For a more in-depth technical analysis of this new malware and its stealer and ransomware characteristics, readers are advised to refer to the original Zscaler report.
ThreatLabz earlier introduced the unique threat category of RAT-as-a-Ransomware in April 2023 at the cybersecurity event, Botconf. Following similar hybrid methods, researchers have now discovered the Stealer-as-a-Ransomware category with RedEnergy. This malware silently steals data and encrypts files, causing severe damage to victims.
The RedEnergy Stealer employs a FAKEUPDATES campaign to trap victims into updating their browsers, subsequently infiltrating their systems, stealing valuable information, and encrypting files. This advanced threat raises concerns of data loss, exposure, or even unauthorized data sales.
Some critical findings from the ThreatLabz investigation include:
The discovery of RedEnergy Stealer and understanding its operations can help organizations bolster their security stance, ensuring effective protection against this new-age malware and similar threats. To fully grasp the technical nuances of RedEnergy Stealer, read the original article on Zscaler.
Source: Zscaler