RedEnergy Stealer
- Malware type
- credential-stealer, ransomware
- Last IoC activity
- 2026-07-19 23:57:07
- Profile updated
- 2026-07-07 15:17:43
Targeted industries: energy-and-utilities financial-services healthcare-and-pharmaceutical technology-and-telecommunications transportation-and-logistics
Context
According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for carrying out ransomware activities.The name of the malware was kept due to the common method names observed during the analysis.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Redenergy Stealer (report)
- zscaler.com — Ransomware Redefined Redenergy Stealer Ransomware Attacks (report)