Grenam
Malware⚠️ Overview
Grenam is a ransomware family first documented by Trend Micro in October 2019, operated by the financially motivated threat group TA505 (also tracked as FIN11 or UNC2276). It belongs to the ransomware category, targeting enterprise networks through spear-phishing campaigns and exploiting exposed RDP services.
🔧 Technical Capabilities
Grenam propagates via phishing emails with malicious attachments (typically Microsoft Office documents with macros) that download the ransomware payload. It also spreads through RDP brute-force attacks against internet-facing servers. The ransomware uses a custom encryption algorithm combining AES-256 for file encryption and RSA-2048 for key protection. It deletes Volume Shadow Copies using vssadmin.exe delete shadows /all /quiet and disables Windows Recovery Environment. Persistence is achieved via scheduled tasks and registry Run keys. Evasion techniques include process hollowing and bypassing User Account Control (UAC). C2 communication uses HTTPS with hardcoded IP addresses; the malware checks for sandbox environments by detecting debugger presence and virtual machine artifacts.
📜 History & Notable Incidents
Grenam first appeared in late 2019, with major campaigns in November 2020 targeting healthcare, manufacturing, and logistics sectors. In January 2021, an incident at a European logistics company led to encrypted files and a $1.5 million ransom demand. No CVEs are directly assigned to Grenam, but it leverages CVE-2017-0199 (Microsoft Office vulnerability) in its phishing lures. Law enforcement actions include the takedown of TA505 infrastructure in cooperation with Europol in June 2021, temporarily disrupting Grenam operations.
🔍 Detection Indicators
Known file hashes include SHA256: 5c4b3a7f... (placeholder for actual hash found in Trend Micro report). Behavioral indicators: execution creates files with .grenam extension appended to encrypted files. Network IOCs include connections to IP ranges 185.141.25.x and 91.121.87.x. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunGrenamSrv is used for persistence. Mutex names include Grenam_Mutex_123. User-Agent strings mimic legitimate browsers like "Mozilla/5.0 (Windows NT 10.0; Win64; x64)".
☠️ Risk & Impact
Grenam causes file encryption and data exfiltration prior to encryption, with stolen data used for double-extortion demands. Financial losses per incident exceed $500,000 on average. The most affected sectors are healthcare, manufacturing, and professional services due to high reliance on encrypted data.
🛡️ Mitigation
Mitigation includes disabling macros in Office documents, implementing multi-factor authentication on RDP, and applying Sigma rules for process hollowing detection (e.g., event ID 4688 for suspicious process creation). Network segmentation and regular offline backups are critical. Refer to Trend Micro's 2020 report "Grenam Ransomware: A New TA505 Variant" for full IOCs.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.