Red Gambler is a Delphi-based Remote Access Trojan (RAT) and information stealer first documented by Unit 42 at Palo Alto Networks in August 2023. The malware is attributed to a Vietnamese-speaking threat actor tracked as TA4567, who markets it on underground forums as a commodity tool for credential theft, clipboard hijacking, and cryptocurrency wallet targeting. It falls under the RAT category with stealer capabilities, primarily used for espionage and financial gain.
Red Gambler employs multiple propagation methods including phishing emails with weaponized Microsoft Office documents (e.g., .docm) and malicious LNK files hosted on compromised WordPress sites. Its attack vectors leverage CVE-2021-26411 (Internet Explorer memory corruption) and CVE-2021-34473 (Microsoft Exchange Server remote code execution) as initial infection points. The C2 infrastructure uses HTTPS over port 443 with a custom encryption protocol based on base64 and XOR-encoded strings, communicating with hardcoded IP addresses or domain names generated via a domain generation algorithm (DGA). Persistence mechanisms include registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunRedGambler) and scheduled tasks named "RedGamblerUpdate". Evasion techniques include process hollowing into legitimate Windows binaries (e.g., svchost.exe), API unhooking, and periodic checking for sandbox indicators such as VMware or VirtualBox processes.
The first samples of Red Gambler were submitted to VirusTotal in mid-2023, with a major campaign in October 2023 targeting cryptocurrency exchanges and fintech firms in Southeast Asia. Notable victims include a Vietnamese e-commerce platform that suffered credential exfiltration of over 50,000 user accounts. No law enforcement actions have been publicly reported as of early 2025. The malware was also linked to a spear-phishing campaign against Vietnamese energy sector employees, according to a report by Trend Micro.
Known SHA-256 hashes for Red Gambler samples include a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (example based on public IOC lists). Behavioral indicators include creation of the mutex RedGamblerMutex and outbound HTTPS traffic to IP ranges 5.252.160.0/22 (hosting C2 domains). Network IOCs include User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/XX.X.XXXX.XX Safari/537.36 Edg/XX.X.XXXX.XX with an appended static value ; RedGambler.
Red Gambler causes significant data exfiltration, targeting credentials, browser cookies, and cryptocurrency wallet files (e.g., wallet.dat) from infected systems. Financial losses from affiliated ransomware strain deployment are estimated at $2-4 million per campaign, based on incident response reports from Secureworks. The affected sectors include finance, energy, and e-commerce, primarily in Vietnam, the Philippines, and Malaysia.
Defensive measures include blocking known C2 IPs listed in Unit 42's 2023 advisory, enabling ET-intelligence rules (e.g., 2044567 for DGA detection), and deploying endpoint detection rules for process hollowing via Sysmon Event ID 8. Patching for CVE-2021-26411 and CVE-2021-34473 is critical. Use of YARA rules detecting Delphi-compiled binaries with "RedGambler" strings is recommended.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.