RedRum
Aliases: Grinch, Thanos, Tycoon
- First seen
- 2020-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 15:17:50
Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
RedRum is a ransomware variant also known under the aliases Grinch, Thanos, and Tycoon. It primarily targets educational institutions, healthcare providers, and financial services, using encryption to hold data hostage until a ransom is paid.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Thanos (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Thanos (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Redrum (report)
- id-ransomware.blogspot.com — Redrum Ransomware (report)