{"id":2930,"date":"2021-06-01T20:03:09","date_gmt":"2021-06-02T01:03:09","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2930"},"modified":"2021-06-01T20:03:10","modified_gmt":"2021-06-02T01:03:10","slug":"epsilon-red-ransomware-targeting-microsoft","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/","title":{"rendered":"Epsilon Red Ransomware targeting Microsoft"},"content":{"rendered":"\n<p>Sophos security researchers announced on Friday, May 28, the detection of a new ransomware called Epsilon Red, following a successful attack on a US hospitality company. Delivered as a final executable payload in a manually controlled attack, the ransomware demanded a payment of 4.29 bitcoin.<\/p>\n\n\n\n<p>According to Sophos, the name and tools of the ransomware attack were unique to the attackers. Although the ransom note resembled the standard message left by the well-known REvil ransomware gang, there were grammatical changes. The gateway was a Microsoft Exchange enterprise server. \u201cIt is not clear if this was enabled by the ProxyLogon exploit or another vulnerability, but the root cause was likely an unpatched server. <\/p>\n\n\n\n<p>According to the cybersecurity firm Malwarebytes, ransomware is a cyber threat that is on the rise, which is designed to block victims&#8217; files and \/ or devices, to later demand a ransom in cryptocurrencies to decrypt them and restore access. In the middle of this May, the analysis firm Elliptic reported that another ransomware group, called DarkSide, managed to raise 90 million dollars in cryptocurrencies, from extortions carried out in a period of nine months. Elliptic obtained this information after identifying 47 Bitcoin addresses associated with the attacking entity.<\/p>\n\n\n\n<p>Epsilon Red begins by killing the processes and services of security tools, databases, backup programs, Microsoft Office applications and email clients, the ransomware deletes all Volume Shadow Copies. The ransomware then steals the Security Account Manager file containing password hashes, deletes Windows event logs, and disables Windows Defender. Finally, suspend the processes, uninstall the security tools and expand the system permissions.<\/p>\n\n\n\n<p>After getting rid of any impediments, Epsilon Red uses Windows Management Instrumentation to install software and run PowerShell scripts that then deploy the main ransomware executable. After this process, what we all already know happens. The executable encrypts the files and steals the data, the victims of the attack are informed and a ransom is demanded.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/\">Zeppelin Ransomware targetting large companies<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/nocry-a-ransomware-inspired-by-wannacry\/\">NoCry new ransomware inspired by WannaCry<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophos security researchers announced on Friday, May 28, the detection of a new ransomware called Epsilon Red, following a successful attack on a US hospitality company. Delivered as a final executable payload in a manually controlled attack, the ransomware demanded a payment of 4.29 bitcoin. According to Sophos, the name and tools of the ransomware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2931,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,105],"class_list":["post-2930","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-02T01:03:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-02T01:03:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"960\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Epsilon Red Ransomware targeting Microsoft\",\"datePublished\":\"2021-06-02T01:03:09+00:00\",\"dateModified\":\"2021-06-02T01:03:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/\"},\"wordCount\":331,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Ransom.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/\",\"name\":\"Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Ransom.jpg\",\"datePublished\":\"2021-06-02T01:03:09+00:00\",\"dateModified\":\"2021-06-02T01:03:10+00:00\",\"description\":\"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Ransom.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Ransom.jpg\",\"width\":1280,\"height\":960},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/epsilon-red-ransomware-targeting-microsoft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Epsilon Red Ransomware targeting Microsoft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog","description":"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/","og_locale":"es_MX","og_type":"article","og_title":"Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog","og_description":"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........","og_url":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-02T01:03:09+00:00","article_modified_time":"2021-06-02T01:03:10+00:00","og_image":[{"width":1280,"height":960,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Epsilon Red Ransomware targeting Microsoft","datePublished":"2021-06-02T01:03:09+00:00","dateModified":"2021-06-02T01:03:10+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/"},"wordCount":331,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/","url":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/","name":"Epsilon Red Ransomware targeting Microsoft - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg","datePublished":"2021-06-02T01:03:09+00:00","dateModified":"2021-06-02T01:03:10+00:00","description":"A new threat called Epsilon Red appears to target Microsoft exchange by exploiting a vulnerability in the exchange.........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Ransom.jpg","width":1280,"height":960},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Epsilon Red Ransomware targeting Microsoft"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2930"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2930\/revisions"}],"predecessor-version":[{"id":2943,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2930\/revisions\/2943"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2931"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}