logo

RedEnergy Stealer

ID: d9df7565-c74a-5586-b419-641b4e83dc03

STIX ID: report--d9df7565-c74a-5586-b419-641b4e83dc03

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This technical analysis describes RedEnergy, a three-stage .NET malware that masquerades as browser updates to gain execution, drops multiple temporary executables, establishes C2 communications (notably domains like 2no.co and downloads from cdn.discord and an observed IP 51.68.11.192), and implements persistence via the Windows startup folder. The payload includes stealer capabilities and a ransomware module that encrypts files with the ".FACKOFF!" extension using Rijndael, deletes volume shadow copies and backup catalogs, alters desktop.ini, drops ransom notes, and exposes multiple IOCs (file hashes, filenames, network indicators) useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.