RedRum

Aliases: Grinch, Thanos, Tycoon

First seen
2020-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 15:17:50

Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

RedRum is a ransomware variant also known under the aliases Grinch, Thanos, and Tycoon. It primarily targets educational institutions, healthcare providers, and financial services, using encryption to hold data hostage until a ransom is paid.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Thanos (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_Ransomware_Thanos (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Redrum (report)
  • id-ransomware.blogspot.com — Redrum Ransomware (report)

External references