logo

Redeemer Ransomware back Action

ID: ed32298d-4778-5135-a477-15e7a0e7da1c

STIX ID: report--ed32298d-4778-5135-a477-15e7a0e7da1c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed Redeemer 2.0 — a ransomware builder distributed via an affiliate program — documenting its features (GUI affiliate toolkit and decrypter, campaign ID/ransom amount fields, XMPP/Tox/email contact options), technical behavior (self-copying to Windows folder, mutex, clearing Windows event logs, deleting shadow copies and backups, killing processes and stopping services, registry modifications to show ransom messages and change file icons, and file encryption using OpenSSL with a ".redeem" extension), and distribution/communication via darkweb forums and Dread. The report includes SHA256/MD5/SHA1 IOCs for components, lists excluded directories/extensions, maps observed MITRE ATT&CK techniques, and provides recommended defensive measures such as offline backups, patching, AV usage, and post-incident containment steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.