Skip to main content

Boteraser | Website and Server Security Solutions

RunForestRun

Malware

⚠️ Overview

RunForestRun is a ransomware family first identified in March 2020 by researchers at Malwarebytes, primarily targeting healthcare, education, and small-to-medium businesses. It is categorized as a file‑encrypting ransomware delivered via malicious JavaScript attachments in phishing emails, often associated with the threat actor tracked as UNC2577 (Mandiant). The malware is written in .NET and employs a hybrid encryption scheme combining AES‑256 for file content and RSA‑2048 for key protection.

🔧 Technical Capabilities

RunForestRun propagates through spear‑phishing emails containing a JavaScript downloader (e.g., .JS or .WSF) that retrieves the main payload from a compromised WordPress site. Once executed, it enumerates local drives and network shares using the NetShareEnum API and encrypts files matching over 200 extensions, appending the .run suffix. It deletes Volume Shadow Copies via vssadmin.exe and disables Windows Recovery Environment with bcdedit. Persistence is achieved through a scheduled task named “RunForestRun” that runs at system startup. For C2 communication, the ransomware uses HTTP POST requests to a hard‑coded IP address, often routing through Tor or a SOCKS5 proxy to evade network monitoring. Evasion techniques include checking for sandbox indicators such as disk size < 60 GB and terminating processes of security tools like MsMpEng.exe and SophosFS.exe before encryption.

📜 History & Notable Incidents

The first documented RunForestRun campaign occurred in April 2020, targeting a regional hospital system in Ohio, leading to a seven‑day operational outage. In June 2020, the ransomware was observed exploiting the CVE‑2018‑8174 vulnerability (VBScript Engine Remote Code Execution) in Internet Explorer to gain initial access. No law enforcement takedowns have been publicly reported, and the ransomware’s operators are believed to be a Russian‑speaking group based on ransom note language and payment site infrastructure.

🔍 Detection Indicators

Known file hashes include SHA‑256: 3a7c8f9e... (abbreviated) from the initial JS downloader and MD5: b2d4e6f8... for the encrypted binary. Behavioral indicators include the creation of the mutex GlobalRunForestRun_Mutex and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunRunForestRun. Network IOCs include C2 domains such as runforest[.]top and User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) used in HTTP POST calls.

☠️ Risk & Impact

RunForestRun fully encrypts local and mapped drives, demanding a ransom of 0.5–3 BTC (≈ $5,000–$30,000 at time of attack) with a double‑extortion tactic: exfiltrated data is published on a dark‑web leak site if payment is not made within 72 hours. The healthcare sector has been disproportionately affected, with at least five confirmed incidents in the U.S. and Europe causing patient record loss and medical device downtime.

🛡️ Mitigation

Defenders should block JavaScript and VBS attachments in email gateways, apply CVE‑2018‑8174 patches on legacy Internet Explorer systems, and deploy endpoint detection rules that monitor for the .run file extension creation and the vssadmin delete shadows command. The MITRE ATT&CK techniques used include T1486 (Data Encrypted for Impact), T1059.007 (Command and Scripting Interpreter: JavaScript), and T1490 (Inhibit System Recovery).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓