logo

ReadText34 Ransomware Incident | Huntress

ID: 343b754a-88a3-563f-98f0-b44cd2d4f045

STIX ID: report--343b754a-88a3-563f-98f0-b44cd2d4f045

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-09-19

Date Updated: 2026-04-28

...
...

Huntress investigated a ransomware incident in which an attacker used compromised Administrator credentials and RDP to deploy a vulnerable TrueSight driver (trend.exe) to crash endpoint security, ran payloads (winppx.exe, readtext34.exe) that attempted kernel driver persistence, opened a reverse shell to 94.198.50.195, and executed file-encryption and recovery-disabling actions (including use of cipher.exe); the incident produced a ransom note (How_to_back_files.html) and multiple IOCs (file SHA256s and contact emails).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.