
Called Advanced Theft Threat as Ransomware red energy It has been confirmed through its LinkedIn page that it is targeting energy businesses, oil and gas, telecommunications, and machinery sectors in Brazil and the Philippines.
In a recent analysis, Zscaler researchers Shatak Jain and Gurkirat Singh noted that the malware “has the ability to steal information from various browsers, enabling the exfiltration of sensitive data while also supporting ransomware activity. It also incorporates various modules to run it.”
The researchers noted that the goal is to combine data theft and encryption to inflict maximum damage to the victim.
The starting point for the multi-stage attack is the FakeUpdates (aka SocGholish) campaign, which fakes a web browser update to trick users into downloading JavaScript-based malware.
What makes it novel is that it uses a trustworthy LinkedIn page to target victims, redirects users who click on the website URL to a fake landing page, and uses appropriate icons (Google Chrome, Microsoft Edge, Mozilla Firefox, etc.) to prompt you to refresh your web browser. , Opera) downloads a malicious executable.
After a successful compromise, the malicious binary is used as a conduit to set persistence and perform actual browser updates, plus a stealer that can covertly gather sensitive information and encrypt stolen files. , leaving the victim at risk of potential data loss. , exposure, and even selling valuable data.

Zscaler said it discovered suspicious interactions taking place over File Transfer Protocol (FTP) connections, raising the possibility that valuable data was being exfiltrated to attacker-controlled infrastructure.
In the final stage, RedEnergy’s ransomware component proceeds to encrypt the user’s data, adding the suffix “.FACKOFF!”. It gives extension to each encrypted file, deletes existing backups and drops ransom note in each folder.
Victims are required to pay 0.005 BTC (approximately $151) to the cryptocurrency wallet mentioned in the note to regain access to their files. His two features, RedEnergy stealer and ransomware, represent the evolution of the cybercrime landscape.
This development is a new RAT-as-a-ransomware threat, with remote access Trojans such as Venom RAT and AnarchyPanel RAT equipped with a ransomware module that locks various file extensions behind an encryption barrier. It also follows the emergence of categories.
“It is extremely important that individuals and organizations exercise extreme caution when accessing websites, especially those linked from their LinkedIn profile,” the researchers said. “The most important way to protect yourself from malicious campaigns like this is to check the authenticity of browser updates and be alert to unexpected file downloads.”