logo

RedEye ransomware: there's more than meets the eye

ID: c67ad6ed-33a8-55b2-835f-0fab91c853b8

STIX ID: report--c67ad6ed-33a8-55b2-835f-0fab91c853b8

Feed Name: Blaze's Security Blog

Threat Score
68/100

Date Published: 2018-06-06

Date Updated: 2026-04-19

Author: Bart

...
...

This report analyzes the RedEye ransomware—linked to the Annabelle author “iCoreX”—highlighting its large, protected binary with embedded media, scare tactics, and destructive behaviors: disabling Task Manager, hiding drives, pseudo-encryption by zero-filling files with a .RedEye extension, and MBR replacement leading to a lock screen; it includes a SHA256 hash of an embedded MBR component, the BTC wallet and Tor payment portal (offline), ransom details, and practical recovery steps, concluding with a recommendation not to pay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.