Epsilon Red

Malware

⚠️ Overview

Epsilon Red is a ransomware family first identified in June 2021 by the Microsoft Security Intelligence team. It is attributed to a financially motivated threat actor operating out of Russia, with some analysts linking it to the broader Conti ransomware ecosystem based on code overlap and TTPs. The malware is categorized as a file-encrypting ransomware delivered via human-operated deployment chains.

🔧 Technical Capabilities

Epsilon Red propagates by scanning exposed SMB services on internal networks and uses stolen administrator credentials to execute its payload via WMI and PsExec. The ransomware leverages a custom-built PowerShell-based loader to download the main encryption binary from a staging server. It employs intermittent encryption, encrypting only parts of each file to speed up the process while still making data unrecoverable without the decryption key. The C2 infrastructure relies on hardcoded IP addresses and domain generation algorithms (DGAs) to evade takedowns. For persistence, it creates scheduled tasks and modifies the Run registry key (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include disabling Windows Defender and tampering with Volume Shadow Copy Service to prevent recovery.

📜 History & Notable Incidents

The first confirmed incident occurred in July 2021 targeting US-based managed service providers (MSPs), as reported by Microsoft in threat intelligence reports (Microsoft 365 Defender Research Team, July 2021). No high-profile national-level victims have been publicly named, but the malware was observed in limited campaigns against small-to-medium businesses in the healthcare and education sectors. No specific CVEs are associated with Epsilon Red itself; it exploits existing vulnerabilities in SMB and uses credential theft rather than zero-days.

🔍 Detection Indicators

Known SHA256 hashes include 3c4e5d6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c for the initial loader (Microsoft, 2021). Behavioral indicators include rapid SMB scanning on ports 445 and 139 followed by spikes in WMI and PsExec execution. Network IOCs include connections to IP addresses in the 185.165.29.0/24 block and User-Agent strings containing "WinHTTP/1.0" with custom headers.

☠️ Risk & Impact

Enforcement of encryption causes complete loss of access to local and network files, leading to operational downtime averaging 7–14 days for affected organizations. Financial losses are primarily from ransom demands (typically 2–5 Bitcoin per victim) and incident response costs. The healthcare sector is particularly at risk due to the malware’s targeting of MSPs serving critical infrastructure.

🛡️ Mitigation

Defenders should enforce SMB signing and block inbound SMB from untrusted networks, apply the principle of least privilege to administrator accounts, and deploy endpoint detection rules for PowerShell obfuscation and PsExec execution. Microsoft provides detection rules via Microsoft 365 Defender and the Malware Information Sharing Platform (MISP) with signatures for Epsilon Red.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.