RedEnergy Stealer-as-a-Ransomware Threat Targeting Energy and Telecom Sectors

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,115
A sophisticated stealer-as-a-ransomware threat dubbed RedEnergy has been spotted in the wild targeting energy utilities, oil, gas, telecom, and machinery sectors in Brazil and the Philippines through their LinkedIn pages.

The malware "possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for carrying out ransomware activities," Zscaler researchers Shatak Jain and Gurkirat Singh said in a recent analysis.

The goal, the researchers noted, is to couple data theft with encryption with the goal of inflicting maximum damage to the victims.

The starting point for the multi-stage attack is a FakeUpdates (aka SocGholish) campaign that tricks users into downloading JavaScript-based malware under the guise of web browser updates.

What makes it novel is the use of reputable LinkedIn pages to target victims, redirecting users clicking on the website URLs to a bogus landing page that prompts them to update their web browsers by clicking on the appropriate icon (Google Chrome, Microsoft Edge, Mozilla Firefox, or Opera), doing so which results in the download a malicious executable.
 

Sandbox Breaker

Level 11
Verified
Top Poster
Well-known
Jan 6, 2022
520
Ransom Stealers! This is getting very very interesting and deadly.
As defenders... We need to prepare for literally every type of threat. It saddens me to see so many other security strategies/threat models only focus on Ransomware. Alot of IT and Security depts are just getting used to the idea of an stealer :LOL:
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,142
Ransom Stealers! This is getting very very interesting and deadly.
As defenders... We need to prepare for literally every type of threat. It saddens me to see so many other security strategies/threat models only focus on Ransomware. Alot of IT and Security depts are just getting used to the idea of an stealer :LOL:

Yup, for now, ransomware and stealers are what we should be protecting our system from
 

Sandbox Breaker

Level 11
Verified
Top Poster
Well-known
Jan 6, 2022
520
Yup, for now, ransomware and stealers are what we should be protecting our system from
What's about RATs. Definately on my scope as my customers are prone to espionage and IP risks. I try to cover all threats. I'll never limit myself to just Ransomware or Stealers. The portfolio of threats is vast and too many to ignore. We cant rely on these Tier 1 SOC's the only perform alert regurgitation.

Things like backdoored system files and replaced kernal modules never get looked at. It takes a good Analyst like @struppigel & @Trident and myself to be really thorough in the investigating and defence process.

Further more: UEFI signature checking, active security research to ensure your not running backdoored Gigabyte Motherboard from that attack. It's all holistic. It takes a true master to understand this.
 
Last edited:

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,142
What's about RATs. Definately on my scope as my customers are prone to espionage and IP risks. I try to cover all threats. I'll never limit myself to just Ransomware or Stealers. The portfolio of threats is vast and too many to ignore. We cant rely on these Tier 1 SOC's the only perform alert regurgitation.

Things like backdoored system files and replaced kernal modules never get looked at. It takes a good Analyst like @struppigel & @Trident and myself to be really thorough in the investigating and defence process.

Further more: UEFI signature checking, active security research to ensure your not running backdoored Gigabyte Motherboard from that attack. It's all holistic. It takes a true master to understand this.
You should have a strong AV/AM or endpoint to protect against malware infection. Also, protect your system from hacking.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top