Threat Advisory

RedEnergy Stealer-as-a-Ransomware Threat Targeting Energy and Telecom Sectors

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

During the Botconf 2023 cybersecurity event, a new threat category called RAT-as-a-Ransomware was unveiled by researchers. However, more recently, researchers have identified another category known as Stealer-as-a-Ransomware. This emerging threat, exemplified by the RedEnergy stealer, combines data theft with encryption to maximize harm and gain control over victims' systems. Industries targeted include energy utilities, oil, gas, telecom, and machinery. These advancements in malware represent a significant shift and advancement beyond traditional ransomware attacks.[/subscribe_to_unlock_form]

Summary:

During the Botconf 2023 cybersecurity event, a new threat category called RAT-as-a-Ransomware was unveiled by researchers. However, more recently, researchers have identified another category known as Stealer-as-a-Ransomware. This emerging threat, exemplified by the RedEnergy stealer, combines data theft with encryption to maximize harm and gain control over victims' systems. Industries targeted include energy utilities, oil, gas, telecom, and machinery. These advancements in malware represent a significant shift and advancement beyond traditional ransomware attacks.[emaillocker id="1283"]

The analyzed sample of Stealer-as-a-Ransomware utilizes a deceptive FAKEUPDATES campaign to lure targets into updating their browsers. Once inside the system, this variant silently steals sensitive information and encrypts compromised files, leaving victims vulnerable to data loss, exposure, or potential sale of their valuable data. The campaign targeted the Philippines Industrial Machinery Manufacturing Company and other industries with notable LinkedIn pages. These pages, which often contain essential company information and website links, make attractive targets for cybercriminals. The campaign utilizes a deceptive redirection technique. When a user attempts to visit the targeted company's website through their LinkedIn profile, they are unknowingly redirected to a malicious website. There, they are prompted to install what appears to be a legitimate browser update but is actually the RedStealer executable.

Infection Chain

The analysis of the RedEnergy malware revealed its dual functionality as a stealer and ransomware. The intentionally obfuscated .NET file evades detection and analysis. It establishes communication with command and control servers using HTTPS, adding an extra layer of encryption and obfuscation. The execution of the malware unfolds in three stages, each serving a specific purpose. The malware masquerades as a legitimate browser update and drops multiple files onto the victim's system. These files include a benign executable that deceives the victim by appearing as a genuine signed update, and a malicious payload responsible for the actual attack. Persistence is achieved through modifications in the Windows startup directory.

Researchers used tools such as Fakenet and Wireshark to gain insights into the malware's behavior and network interactions. Suspicious activity involving File Transfer Protocol (FTP) raised concerns about potential data exfiltration and file uploads. The final stage of the payload involves encryption of the user's files, appending the ".FACKOFF!" extension, and demanding a ransom for their release. The malware alters the desktop.ini file to manipulate how the file system folders are displayed, further concealing its presence. The payload also performs actions to hinder data recovery, such as deleting data from the shadow drive and targeting Windows backup plans. It exfiltrates the user's data and modifies boot configurations to disable recovery options. Antivirus information is gathered and sent to the Command and Control (CnC) server, and a ransom note is dropped in encrypted folders.

This detailed analysis provides insights into the technical aspects of the RedEnergy malware, aiding in understanding its behavior and enabling the development of effective countermeasures. It emphasizes the need for caution when accessing websites linked from LinkedIn profiles, verifying the authenticity of browser updates, and being wary of unexpected file downloads to protect against these malicious campaigns.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/07/redenergy-stealer-as-ransomware-threat.html

[/emaillocker]
crossmenu