RedRansomware is a ransomware group first observed in June 2024, focusing its operations on large enterprises by demanding hefty ransoms and employing double extortion tactics, which involve threatening to leak stolen data if payment is not made. Their operational methodology includes extensive reconnaissance and lateral movement within compromised networks prior to data encryption. This group distinguishes itself through its organized approach to network infiltration, leveraging vulnerabilities, and social engineering to gain initial access, suggesting a structured and deliberate attack methodology.
Tecnicas MITRE
T1059.001, T1078.001, T1562.001, T1486, T1489
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Antigua and BarbudaArgentinaBelgiumCanadaGermanyDenmarkSpainIndiaItalyMexico
Sectores atacados
Education (1)
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational ServicesEnergy & Utilities