logo

What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis

ID: f0b17ce4-dc3f-5e00-b9bf-463f271c4521

STIX ID: report--f0b17ce4-dc3f-5e00-b9bf-463f271c4521

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2022-09-02

Date Updated: 2026-04-27

...
...

The report provides a technical analysis of the Redeemer ransomware (up to version 2.0) including its builder, encryption (AES-256 + RSA), evasion and persistence techniques (self-copying to system folders, mutex, hiding, Winlogon registry changes), destructive actions (deleting shadow copies and clearing event logs), termination of security and backup services, multithreaded file encryption across local and network drives, ransom collection workflow (Monero), attribution to the actor “Cerebrate,” and associated IOCs and terminated process/service lists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.