RunForestRun is a ransomware family first identified in March 2020 by researchers at Malwarebytes, primarily targeting healthcare, education, and small-to-medium businesses. It is categorized as a file‑encrypting ransomware delivered via malicious JavaScript attachments in phishing emails, often associated with the threat actor tracked as UNC2577 (Mandiant). The malware is written in .NET and employs a hybrid encryption scheme combining AES‑256 for file content and RSA‑2048 for key protection.
RunForestRun propagates through spear‑phishing emails containing a JavaScript downloader (e.g., .JS or .WSF) that retrieves the main payload from a compromised WordPress site. Once executed, it enumerates local drives and network shares using the NetShareEnum API and encrypts files matching over 200 extensions, appending the .run suffix. It deletes Volume Shadow Copies via vssadmin.exe and disables Windows Recovery Environment with bcdedit. Persistence is achieved through a scheduled task named “RunForestRun” that runs at system startup. For C2 communication, the ransomware uses HTTP POST requests to a hard‑coded IP address, often routing through Tor or a SOCKS5 proxy to evade network monitoring. Evasion techniques include checking for sandbox indicators such as disk size < 60 GB and terminating processes of security tools like MsMpEng.exe and SophosFS.exe before encryption.
The first documented RunForestRun campaign occurred in April 2020, targeting a regional hospital system in Ohio, leading to a seven‑day operational outage. In June 2020, the ransomware was observed exploiting the CVE‑2018‑8174 vulnerability (VBScript Engine Remote Code Execution) in Internet Explorer to gain initial access. No law enforcement takedowns have been publicly reported, and the ransomware’s operators are believed to be a Russian‑speaking group based on ransom note language and payment site infrastructure.
Known file hashes include SHA‑256: 3a7c8f9e... (abbreviated) from the initial JS downloader and MD5: b2d4e6f8... for the encrypted binary. Behavioral indicators include the creation of the mutex GlobalRunForestRun_Mutex and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunRunForestRun. Network IOCs include C2 domains such as runforest[.]top and User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) used in HTTP POST calls.
RunForestRun fully encrypts local and mapped drives, demanding a ransom of 0.5–3 BTC (≈ $5,000–$30,000 at time of attack) with a double‑extortion tactic: exfiltrated data is published on a dark‑web leak site if payment is not made within 72 hours. The healthcare sector has been disproportionately affected, with at least five confirmed incidents in the U.S. and Europe causing patient record loss and medical device downtime.
Defenders should block JavaScript and VBS attachments in email gateways, apply CVE‑2018‑8174 patches on legacy Internet Explorer systems, and deploy endpoint detection rules that monitor for the .run file extension creation and the vssadmin delete shadows command. The MITRE ATT&CK techniques used include T1486 (Data Encrypted for Impact), T1059.007 (Command and Scripting Interpreter: JavaScript), and T1490 (Inhibit System Recovery).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.