{"id":6464,"date":"2024-04-23T10:03:28","date_gmt":"2024-04-23T16:03:28","guid":{"rendered":"https:\/red-ransomware-group-a-new-threat-actor\/"},"modified":"2025-06-05T13:04:12","modified_gmt":"2025-06-05T19:04:12","slug":"red-ransomware-group-a-new-threat-actor","status":"publish","type":"post","link":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/","title":{"rendered":"Red Ransomware Group, a new threat actor"},"content":{"rendered":"<p>Recently Beacon Lab has conducted an investigation of an incident, in which a new ransomware group, named Red Ransomware Group according to their public blog, or also Red CryptoApp (because of the encryption extension), has been discovered. Like most of today&#8217;s ransomware groups, they use a double extortion strategy: file encryption and data exfiltration and their respective publication in a public blog (&#8220;Hall of Shame&#8221;). In this article we will discuss the tactics, techniques and procedures (TTP) of this new group, as well as some characteristics of their operation.  <\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-23-000935.png\" alt=\"\" width=\"283\" height=\"340\"><\/p>\n<h3><strong>Operation of Red Ransomware Group:<\/strong><\/h3>\n<p>At the time of the investigation, the group&#8217;s public blog (&#8220;Hall of Shame&#8221;) listed only about ten victims. Apparently, the first victims were posted on the portal on March 5, 2024, with the group&#8217;s attacks beginning at the earliest in mid-February 2024. Like most ransomware groups, this group leaves a ransom note in txt format, with the name HOW_TO_RESTORE_FILES.REDCryptoApp.txt on all encrypted folders. The note contains a reference to the private negotiation portal, and a unique ID for each client. <\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-5917\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214239-1.png\" alt=\"\" width=\"1418\" height=\"882\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214239-1.png 1418w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214239-1-300x187.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214239-1-1024x637.png 1024w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214239-1-768x478.png 768w\" sizes=\"(max-width: 1418px) 100vw, 1418px\" \/><\/p>\n<p>The negotiation portal consists of a chat with the group&#8217;s support team, as well as the payment details (wallet address and amount demanded, as well as some details of the attack). The exfiltrated data size data is most likely false. According to other analyzed notes, the wallet address is apparently the same for several victims. So far, no payments have been made to the wallet.   <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-214702-1024x393.png\" alt=\"\" width=\"849\" height=\"326\"><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-22-215118_anonimizado-1024x508.png\" alt=\"\" width=\"849\" height=\"421\"><br \/>\nAn analysis of this group&#8217;s public blog suggests that this is a new group, which began operations recently. At the time of the blog analysis, 12 victims were listed, all with the same date. In the last few days, only one new victim has been added. Although the download links for the published files currently point to a different address than the public blog and are broken, at the time of analysis the links were functional and it was found that they did indeed allow the download of legitimate exfiltrated files from the victims.   <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Captura-de-pantalla-2024-03-11-213559-1024x447.png\" alt=\"\" width=\"1024\" height=\"447\"><\/p>\n<p>It is striking that, in some cases, the description of some victims does not actually correspond to the victim company, but to a description of another company with a similar name, demonstrating a certain carelessness when listing the company; it also demonstrates a semi-manual Google search process, prone to error.<\/p>\n<h4><strong>Chain of infection and techniques:<\/strong><\/h4>\n<hr>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/diagram.jpg\" alt=\"\" width=\"864\" height=\"475\"><\/p>\n<h4><strong>Initial attack vector:<\/strong><\/h4>\n<p>In the investigated incident, Red Ransomware Group was found to exploit vulnerability <strong>CVE-2023-47246<\/strong> in <strong>SysAid<\/strong> software that had been publicly reported in early November 2023. It is a Path Traversal vulnerability that leads to code execution affecting SysAid on-premise versions prior to 23.3.36. Through this vulnerability, the actor was able to upload webshells to the <strong>SysAid<\/strong> root directory and take control of the server. The webshells were found in the &#8220;managerap&#8221; path, inside the root directory of <strong>SysAid&#8217;<\/strong>s Tomcat server, trying to camouflage themselves with the manager folder that is part of the real structure of the application. Several webshells were found, among them, Jsp File Browser, which, among other things, allows exploring the file system, reading, creating and modifying files, executing commands, uploading artifacts, etc. This webshell is used by the group to upload, execute and install other remote control software (RMM) on the server.  <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/browser06.png\" alt=\"\" width=\"537\" height=\"412\"><\/p>\n<p>It cannot be ruled out that the group uses access previously acquired from other criminal groups that have previously compromised and gained access to servers, and that usually offer it in underground markets (&#8220;Access brokers&#8221;), since in the particular case investigated, there were already some webshells previously injected, all as a result of the exploitation of the mentioned <strong>SysAid<\/strong> vulnerability.<\/p>\n<h4>Command and control:<\/h4>\n<p>It has been observed that the group uses the JWrapper tool to deploy <strong>SimpleHelp Remote Access<\/strong>, a remote control software intended to provide remote support, in a client-server, self-hosted model. The SimpleHelp client connects to a server under the attacker&#8217;s control. In this case, the attacker&#8217;s server was located at <a href=\"https:\/\/64.31.63.240\/access\">https:\/\/64.31.63.240\/access,<\/a> hosted by LimeStone Neworks (France).  <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen2.png\" alt=\"\" width=\"364\" height=\"166\"><\/p>\n<p>We also detected other remote control tools, which had been installed using the <strong>NSSM<\/strong><strong>(Non-sucking Service Manager<\/strong>) tool, a legitimate tool for managing services on Windows operating systems. The executable of this program was located in <strong>C:windowssystem32, <\/strong>masked under the name <strong>HealthReport.exe.<\/strong> NSSM installed and executed <strong>AnyDesk<\/strong>, another popular remote control program, and a malicious DLL <strong>c:windowssystem32users.dll <\/strong>(Hash SHA256: e37b95bb9bee64cc0313eaad8a0269493745f89413bd78b58bb3b479b36084ae). This DLL is waiting for commands, which are sent to it from <a href=\"https:\/\/cl1p.net\/101012\">https:\/\/cl1p.net\/101012.<\/a> Cl1p.net is a free online tool that acts as an online clipboard where the attacker writes a command that is then read from the compromised server, thus being able to send commands to the server, evading security tools, which are not able to inspect the command that is sent. We also found that ScreenConnect was used, with a connection ID b5be755f21077092 It is not entirely clear if all of these tools are installed by Red Ransomware Group, or if some of them were provided by an Access Broker that had previously gained control over the compromised <strong>SysAid<\/strong> server. It was possible to verify the use of AnyDesk and ScreenConnect as a secondary C&amp;C mechanism by this group. All command and control tools had been installed as system services and configured at startup to allow for greater persistence.  <\/p>\n<h4>Internal scanning:<\/h4>\n<p>The group uses SoftPerfect Network Scanner (netscan.exe) to scan other computers on the network. It is a portable scanner that allows you to discover hosts, scan ports, discover shared folders, and extract computer details via WMI, SNMP, HTTP, SSH and PowerShell. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen3.png\" alt=\"\" width=\"469\" height=\"369\"><\/p>\n<p>We also checked the use of Nmap and Advaced IP Scanner, but it is very likely that they were installed and made available by other Access Brokers.<\/p>\n<h4>Lateral movement:<\/h4>\n<p>To move laterally to other computers on the network, the Red Ransomware Group mostly uses Pass the Hash. To dump hashes the group uses the <strong>Procdump<\/strong> tool, a command line tool developed by Microsoft, part of SysInternals, which is used to create dumps of processes on Windows systems. In this case, the actor obtains the hashes from the dump of the lsass.exe process.  <\/p>\n<pre style=\"padding-left: 40px;\">C:Programdatap64.exe -accepteula -ma lsass.exe C:Programdatao.dmp<\/pre>\n<p>The dump allows him to obtain the domain administrator hashes, which will then be used to connect to various machines to deploy artifacts, including the encrypter. Using the SMBExec tool, the attacker <strong>enables Restricted Admin Mode<\/strong>, which allows him to perform Pass-the-Hash lateral movements via RDP: Obfuscated command:<\/p>\n<pre style=\"padding-left: 40px;\">%COMSPEC% \/Q \/c echo powershell -exec bypass -enc TgBlAHcALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgAC0AUABhAHQAaAAgACIASABLAEwATQA6AFwAUwB5AHMAdABlAG0AXABDAHUAcgByAGUAbgB0AEMAbwBuAHQAcgBvAGwAUwBlAHQAXABDAG8AbgB0AHIAbwBsAFwATABzAGEAIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBSAGUAcwB0AHIAaQBjAHQAZQBkAEEAZABtAGkAbgAiACAALQBWAGEAbAB1AGUAIAAiADAAIgAgAC0AUAByAG8AcABlAHIAdAB5AFQAeQBwAGUAIABEAFcATwBSAEQAIAAtAEYAbwByAGMAZQA= ^&gt; \\127.0.0.1C$__output 2^&gt;^&amp;1 &gt; %TEMP%execute.bat &amp; %COMSPEC% \/Q \/c %TEMP%execute.bat &amp; del %TEMP%execute.bat<\/pre>\n<p>Deofuscated command:<\/p>\n<pre style=\"padding-left: 40px;\">%COMSPEC% \/Q \/c echo powershell -exec bypass -enc New-ItemProperty -Path \"HKLM:SystemCurrentControlSetControlLsa\" -Name \"DisableRestrictedAdmin\" -Value \"0\" -PropertyType DWORD -Force &gt; \\127.0.0.1C$__output 2^&gt;^&amp;1 &gt; %TEMP%execute.bat &amp; %COMSPEC% \/Q \/c %TEMP%execute.bat &amp; del %TEMP%execute.bat\n<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen4.png\" alt=\"\" width=\"624\" height=\"162\"><\/p>\n<h4>Exfiltration:<\/h4>\n<p>Red Ransomware Group uses the well-known <strong>Rclone<\/strong> tool, a command-line tool for synchronizing files and directories from a computer with the most popular cloud content hosting providers. The actor sends the exfiltrated data to Put.io, a well-known cloud hosting service that has been used by other groups in the past. In the case under investigation, the exfiltration took place only on one of the affected servers.  <\/p>\n<p><strong> <\/strong><\/p>\n<h4>Persistence:<\/h4>\n<p>To ensure persistence, the actor creates several users, both local and workgroup, which were added to the local administrator groups of the affected computers, using native Windows commands (quser and net):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-23-023923.png\" alt=\"\" width=\"634\" height=\"88\"><br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Captura-de-pantalla-2024-03-14-181102.png\" alt=\"\" width=\"630\" height=\"668\"><\/p>\n<h4>Evasion:<\/h4>\n<p>We have observed that the group uses the well-known anti-rootkit tools <strong>GMER<\/strong> and <strong>AVAST aswArPot,<\/strong> masked under the name un63td1n.exe and aswQP_Avar.sys respectively. To interrupt the processes corresponding to the Antivirus \/ EDR, thus evading any protection or blocking that these may cause. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen5.png\" alt=\"\" width=\"402\" height=\"177\"><\/p>\n<h4>Impact:<\/h4>\n<p>To deploy the ransomware, the attacker uses <strong>PDQ Deploy<\/strong>, a tool used for mass deployment of scripts to multiple devices.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen6.png\" alt=\"\" width=\"469\" height=\"106\"><\/p>\n<p>With this tool, the attacker builds an XML that is deployed and executes various actions on all the servers to which he has previously gained access, among them:<\/p>\n<ol>\n<li>Eliminate the records of the most known EDRs, preventing their initiation.<\/li>\n<li>Ensuring autostart of AnyDesk and Screenconnect<\/li>\n<li>Creation of an <strong>ekrnEpfwFF <\/strong>service that ensures the start of AAA.ps1, previously created, with the restart of the operating system:\n<ol>\n<li>The script AAA.ps1, which is obfuscated, copies the binary corresponding to the encrypter in the path C:programdata, with the name <strong>exe<\/strong>, creates and executes some powershell scripts (S01.ps1 and S02.ps2) in charge of the encrypter execution and then deletes some traces, including these scripts.<\/li>\n<\/ol>\n<\/li>\n<li>Creation of user <strong>Administrator2 (<\/strong>password P@ssw0rd1234!), in Autologon mode<\/li>\n<li>SMB connection to target server to be encrypted, with Workgroup <strong>test<\/strong> user (P@ssw0rd123)<\/li>\n<li>Copy AAA.ps1 script to C:programdata of each computer to be encrypted.<\/li>\n<\/ol>\n<p>The encrypter is copied with the name AAQQ.exe. The executable is packaged with UPX and is written in Go. Its hash (SHA-256) is: ba84c8200820016298ad5e15a5f3eb9ab608491963ff333ae0e1267ac48ac909606e  <\/p>\n<p><strong>Other interesting facts:<\/strong><\/p>\n<p>To execute some of the post-exploitation actions after connecting via SimpleHelp, the group uses Win-PTY (winpty-agent.exe, <a href=\"https:\/\/github.com\/rprichard\/winpty\">https:\/\/github.com\/rprichard\/winpty)<\/a>, a tool that provides a Unix-like pseudo-terminal interface to communicate with Windows console programs and send CMD commands in a more convenient way. Powershell Script Obfuscation: All Powershell scripts of this attacker are obfuscated with a simple character replacement algorithm.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-5935\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-23-180120.png\" alt=\"\" width=\"424\" height=\"181\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-23-180120.png 525w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/Screenshot-2024-04-23-180120-300x128.png 300w\" sizes=\"(max-width: 424px) 100vw, 424px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Script S01.ps1: Although, the attacker deletes said file, it was possible to obtain it from the AAA.ps1 script that generates it. It is the script in charge of deleting backup copies and removing traces, mainly. It consists of 7 sections, which execute a series of actions, such as:<\/p>\n<ul>\n<li>Disables Windows Defender and all its modules (automatic sample submission, real-time protection, intrusion prevention, etc.)<\/li>\n<li>Set full control permissions (Everyone:F) on various locations, including disk drives, folders in the root of C: (excluding those related to the system), desktop folders, downloads and documents for each user.<\/li>\n<li>Stops and disables a number of enumerated services and processes, matching a list of words (Veeam, Barracuda, Trend, Cylance, sql, etc).<\/li>\n<li>Using vssadmin.exe removes all shadow copies on the system.<br \/>\n(except for the C: partition), and to adjust the maximum shadow storage size on all available drives (reduce it to 401MB).<br \/>\nThen make sure that they have been removed again, using the wmic and Get-WmiObject commands.  <\/li>\n<li>With bcdedit disable system recovery and set the boot state policy to ignore all failures.<\/li>\n<li>The Get-EventLog and Clear-EventLog commands clear the event logs from the system.<\/li>\n<\/ul>\n<p>Script S02.ps1: This is the script in charge of executing the encrypter itself. To do so, it defines a key that appears to be an MD5 hash. We could not determine if it is a unique key for each victim or if it is a universal key. The encryptor is then run in a loop for each drive as follows:<\/p>\n<pre>C:ProgramdataAAQQ.exe &lt;clave&gt; &lt;unidad_disco&gt;<\/pre>\n<p>It can be seen that, on disk C:, the attacker avoids encrypting any folder containing &#8220;Windows&#8221;, &#8220;Program&#8221;, &#8220;users&#8221;, &#8220;driver&#8221;, &#8220;boot&#8221;, probably to avoid interfering with or corrupting the operating system.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2024\/04\/Imagen7.png\" alt=\"\" width=\"743\" height=\"313\"><\/p>\n<h2>Conclusions:<\/h2>\n<hr>\n<p>This new group, while still with a limited number of victims, will most likely continue to grow its operations and victims. Considering that, according to Shodan, there are currently more than 500 SYSAid servers exposed to the Internet, and that the group may expand its arsenal of initial access exploits, it is possible that the group&#8217;s activities will begin to claim more victims. Like other current groups, this actor leverages many legitimate IT management tools (Living-off-the-Land, LotL) to reduce the likelihood of detection by seeking to go undetected. In addition, it demonstrates a high degree of automation of its actions and tasks, reducing the victim&#8217;s reaction time between initial compromise and encryption of all systems. To minimize the chances of being a victim of this type of group, Beaconlab recommends: <\/p>\n<ul>\n<li>Always keep software up to date, with the latest security patches, especially applications and services exposed to the Internet.<\/li>\n<li>Use EDR\/XDR solutions that allow early detection of signs of compromise.<br \/>\nRemember that endpoint protection solutions, even if they have the capacity to block threats, must be permanently monitored by specialized analysts; likewise, remember to review the configuration frequently to ensure that protection levels are adequate. <\/li>\n<li>Implement a centralized visibility and traceability strategy that enables early detection of any type of intrusion at different layers.<br \/>\nKeep in mind that attackers often seek to disrupt EDR\/XDR processes, and defense and visibility in depth is critical to address this risk. <\/li>\n<li>Perform hardening according to some baseline, e.g. CIS Benchmarks, for each system and according to each use or application of that system.<\/li>\n<li>Perform an exhaustive review of users with administrator privileges and eliminate those that are not strictly necessary, limiting it to the minimum necessary personnel.<\/li>\n<li>Implement a protection strategy against lateral movement techniques (Pass-the-Hash, Pass-the-Ticket or similar), taking into account that these exploit design weaknesses in the AD architecture itself. Microsoft has published an official guide to address this:\n<ul>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=36036\"><em>https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=36036<\/em><\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>Indicators of Commitment (IoC):<\/h3>\n<div id=\"footable_parent_5906\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_0\" data-footable_id=\"5906\" data-filter-delay=\"1000\" aria-label=\"Red Ransomware Group\"            id=\"footable_5906\"\n           data-unique_identifier=\"ninja_table_unique_id_892513389_5906\"\n           class=\" foo-table ninja_footable foo_table_5906 ninja_table_unique_id_892513389_5906 ui table nt_type_ajax_table fixed selectable striped compact vertical_centered footable-paging-right\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                    <\/colgroup>\n            <\/table>\n    \n    \n    \n<\/div>\n\n<p>To download the IoCs you can redirect to the following link <a href=\"https:\/\/raw.githubusercontent.com\/Beacon-Lab-IR\/beacon-site-assets\/main\/files\/red-ransomware-ioc.csv\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently Beacon Lab has conducted an investigation of an incident, in which a new ransomware group, named Red Ransomware Group according to their public blog, or also Red CryptoApp (because of the encryption extension), has been discovered. Like most of today&#8217;s ransomware groups, they use a double extortion strategy: file encryption and data exfiltration and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6333,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[48],"tags":[84,92,91,89,93,90,88],"class_list":["post-6464","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-beaconlab-en","tag-cryptoapp-network","tag-cyber-incident-en","tag-network","tag-ransomware-en","tag-ransomware-group-en","tag-red-ransomware-en"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"CSIRT by Cybolt - New ransomware group &quot;Red Ransomware Group&quot; or &quot;Red CryptoApp&quot; investigated by Beacon Lab; TTP analysis and characteristics of its operation.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Gabriela Ratti\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Red Ransomware Group, a new threat actor - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"CSIRT by Cybolt - New ransomware group &quot;Red Ransomware Group&quot; or &quot;Red CryptoApp&quot; investigated by Beacon Lab; TTP analysis and characteristics of its operation.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-04-23T16:03:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-06-05T19:04:12+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Red Ransomware Group, a new threat actor - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"CSIRT by Cybolt - New ransomware group &quot;Red Ransomware Group&quot; or &quot;Red CryptoApp&quot; investigated by Beacon Lab; TTP analysis and characteristics of its operation.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#blogposting\",\"name\":\"Red Ransomware Group, a new threat actor - Beacon Lab\",\"headline\":\"Red Ransomware Group, a new threat actor\",\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/image.png\",\"width\":1024,\"height\":576},\"datePublished\":\"2024-04-23T10:03:28-06:00\",\"dateModified\":\"2025-06-05T13:04:12-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#webpage\"},\"articleSection\":\"Uncategorized, beaconlab, CryptoApp Network, cyber-incident, network, ransomware, ransomware-group, red-ransomware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#listItem\",\"name\":\"Red Ransomware Group, a new threat actor\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#listItem\",\"position\":3,\"name\":\"Red Ransomware Group, a new threat actor\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/\",\"name\":\"Gabriela Ratti\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d08a40ef41baf3a5b15cfd3f9d93069fcd1db17fc70c0a93c3133c7b2eb3a3ab?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Gabriela Ratti\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/\",\"name\":\"Red Ransomware Group, a new threat actor - Beacon Lab\",\"description\":\"CSIRT by Cybolt - New ransomware group \\\"Red Ransomware Group\\\" or \\\"Red CryptoApp\\\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/image.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#mainImage\",\"width\":1024,\"height\":576},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/red-ransomware-group-a-new-threat-actor\\\/#mainImage\"},\"datePublished\":\"2024-04-23T10:03:28-06:00\",\"dateModified\":\"2025-06-05T13:04:12-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Red Ransomware Group, a new threat actor - Beacon Lab","description":"CSIRT by Cybolt - New ransomware group \"Red Ransomware Group\" or \"Red CryptoApp\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.","canonical_url":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#blogposting","name":"Red Ransomware Group, a new threat actor - Beacon Lab","headline":"Red Ransomware Group, a new threat actor","author":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","width":1024,"height":576},"datePublished":"2024-04-23T10:03:28-06:00","dateModified":"2025-06-05T13:04:12-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#webpage"},"isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#webpage"},"articleSection":"Uncategorized, beaconlab, CryptoApp Network, cyber-incident, network, ransomware, ransomware-group, red-ransomware"},{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#listItem","name":"Red Ransomware Group, a new threat actor"},"previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#listItem","position":3,"name":"Red Ransomware Group, a new threat actor","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"Person","@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author","url":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/","name":"Gabriela Ratti","image":{"@type":"ImageObject","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/d08a40ef41baf3a5b15cfd3f9d93069fcd1db17fc70c0a93c3133c7b2eb3a3ab?s=96&d=mm&r=g","width":96,"height":96,"caption":"Gabriela Ratti"}},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#webpage","url":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/","name":"Red Ransomware Group, a new threat actor - Beacon Lab","description":"CSIRT by Cybolt - New ransomware group \"Red Ransomware Group\" or \"Red CryptoApp\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#breadcrumblist"},"author":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"creator":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#mainImage","width":1024,"height":576},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/#mainImage"},"datePublished":"2024-04-23T10:03:28-06:00","dateModified":"2025-06-05T13:04:12-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Red Ransomware Group, a new threat actor - Beacon Lab","og:description":"CSIRT by Cybolt - New ransomware group &quot;Red Ransomware Group&quot; or &quot;Red CryptoApp&quot; investigated by Beacon Lab; TTP analysis and characteristics of its operation.","og:url":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","article:published_time":"2024-04-23T16:03:28+00:00","article:modified_time":"2025-06-05T19:04:12+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Red Ransomware Group, a new threat actor - Beacon Lab","twitter:description":"CSIRT by Cybolt - New ransomware group &quot;Red Ransomware Group&quot; or &quot;Red CryptoApp&quot; investigated by Beacon Lab; TTP analysis and characteristics of its operation.","twitter:creator":"@BeaconLabMX","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png"},"aioseo_meta_data":{"post_id":"6464","title":null,"description":"#tagline #separator_sa New ransomware group \"Red Ransomware Group\" or \"Red CryptoApp\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":"#post_title #separator_sa #site_title","og_description":"#tagline #separator_sa New ransomware group \"Red Ransomware Group\" or \"Red CryptoApp\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.","og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","og_image_width":"0","og_image_height":"0","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"featured","twitter_image_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/04\/image.png","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":"#post_title #separator_sa #site_title","twitter_description":"#tagline #separator_sa New ransomware group \"Red Ransomware Group\" or \"Red CryptoApp\" investigated by Beacon Lab; TTP analysis and characteristics of its operation.","schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-10-11 18:30:13","updated":"2025-09-24 05:43:25","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tRed Ransomware Group, a new threat actor\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Uncategorized","link":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/"},{"label":"Red Ransomware Group, a new threat actor","link":"https:\/\/beaconlab.us\/en\/red-ransomware-group-a-new-threat-actor\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/comments?post=6464"}],"version-history":[{"count":4,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6464\/revisions"}],"predecessor-version":[{"id":10779,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6464\/revisions\/10779"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/6333"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=6464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/categories?post=6464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/tags?post=6464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}