RedEye ransomware: there's more than meets the eye
ID: c67ad6ed-33a8-55b2-835f-0fab91c853b8
STIX ID: report--c67ad6ed-33a8-55b2-835f-0fab91c853b8
Feed Name: Blaze's Security Blog
This report analyzes the RedEye ransomware—linked to the Annabelle author “iCoreX”—highlighting its large, protected binary with embedded media, scare tactics, and destructive behaviors: disabling Task Manager, hiding drives, pseudo-encryption by zero-filling files with a .RedEye extension, and MBR replacement leading to a lock screen; it includes a SHA256 hash of an embedded MBR component, the BTC wallet and Tor payment portal (offline), ransom details, and practical recovery steps, concluding with a recommendation not to pay.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
