A new version of Ransomware as a Service (RaaS) Redeemer was launched earlier this summer. This ransomware builder gained popularity in June 2021 when its creator released version 1.0 of the programming code on a forum.

Table of Contents

About Redeemer 2.0

Redeemer stands out from other RaaS because it is free and accessible to everyone. Its author, Cerebrate, designed the "product" to receive 20% of the ransom paid to an affiliate who used Redeemer. To reverse the encryption process if the victim pays the ransom, the affiliate needs a combination of the master key (provided by the author, Cerebrate) and their own private key.

Redeemer is accessible on a Dread dark web site. After running with administrator privileges and encrypting the victims' files with a .redeem extension, a ransom note demanding payment in Monero cryptocurrency is generated.

The recent 2.0 version features a new graphical interface that allows the affiliate to build the ransomware executable and the decryption tool, as well as a campaign tracking system, while all instructions for its use are included in a ZIP file.

Detecting Redeemer with the TEHTRIS XDR Platform

Since the Redeemer toolkit is freely accessible, anyone—even with low hacking skills—can participate in extortion using encryption. This in itself poses a threat to entities that are not sufficiently protected, as is often the case in the vital healthcare sector or for small businesses with tight cybersecurity budgets.

To meet the needs of small and medium-sized businesses defending against aggressive cyber threats, TEHTRIS OPTIMUS offers 100% online detection and protection for computers and servers, with simplified and rapid deployment while ensuring high-performance security.

TEHTRIS OPTIMUS combines EDR (Endpoint Detection and Response) and NGAV (Next Generation AntiVirus) features to detect and neutralize known and unknown threats in real time, without any human interaction. This technology includes a single agent with pre-configurations, can be deployed in a short time, and offers an optimized user experience.

How does TEHTRIS EDR protect devices against a threat like Redeemer?

TEHTRIS Dynamic Analysis: Cyber Threat Intelligence

Using a security solution on all endpoints—in addition to raising staff awareness about cybersecurity and ensuring that offline backups are kept up to date—is essential to prevent an attack from ransomware like Redeemer.

Any file executed on a device protected by TEHTRIS EDR (Endpoint Detection and Response) is automatically analyzed in the TEHTRIS Cyber Threat Intelligence database.

TEHTRIS CTI is both a knowledge base and a malware analysis tool equipped with artificial intelligence, static and dynamic analysis capabilities, and a direct, secure link to an external database. If malware like Redeemer is launched on a machine, it will be identified as highly dangerous and will immediately trigger an alert (and instantly neutralize the process if the EDR system is in remediation mode).

Analysis of Redeemer’s SHA256 in TEHTRIS CTI

TEHTRIS Sandbox dynamic analysis detected several risky behaviors, such as the Shared Modules execution technique to run malicious payloads (T1129 in the MITRE ATT&CK matrix), detection evasion by using Software Packing to modify the file signature (T1027.002) and then deobfuscating it (T1140), or obfuscating traffic to the command and control (C&C) server to make it harder to detect (T1001).

Isolating an infected machine with TEHTRIS SOAR

Another layer of protection offered by the TEHTRIS XDR Platform is the implementation of a playbook on the SOAR (Security Orchestration, Automation, and Response). Since ransomware uses lateral movement to access high-value data in a compromised network, SOAR allows you to automatically isolate a device to prevent the threat from spreading across the entire network, while keeping an eye on events occurring on the infected machine via TEHTRIS XDR.

In the case of Redeemer, a custom playbook was implemented with the following features—after a testing phase to ensure it would not trigger false positives:

The scenario begins with a Lucene query that accounts for Redeemer's specific characteristics (such as the names of files and folders where the malware copies itself on the victim's machine, and the command lines Redeemer uses to delete shadow copies, the backup catalog, and system state backups prior to encryption to prevent the victim from restoring data...). If the query conditions are met, an automatic action will isolate the device from the network after recording a map of network connections and running processes on the endpoint. The results will then be available in the Alerts and Events tab.

These indicators will help gather information for the incident investigation.

As with Redeemer 1.0, the author announced that version 2.0 will "go open source" if they ever "lose interest," which would create new opportunities for low-skilled cybercriminals.

It is crucial to anticipate these types of attacks: performing regular offline backups, updating systems, and using cybersecurity protection are imperative measures to protect against RaaS operations.

TEHTRIS protects your company from known and unknown threats by automatically neutralizing ransomware and 0-day attacks in real time. Our solutions are modular and can be deployed individually or as a suite within the TEHTRIS XDR platform.

https://www.bleepingcomputer.com/news/security/new-redeemer-ransomware-version-promoted-on-hacker-forums/ (07/21/22)
https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action/ (07/20/22)
TEHTRIS Threat Research weekly feed for customers (08/05/22)

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all