A detailed incident report covering a ReadText34 ransomware attack observed by Huntress analysts in September 2024. The threat actor gained initial access using stolen Administrator credentials, enabled RDP remotely, then deployed TrueSightKiller (a known vulnerable driver) via a BYOVD technique to crash Trend Micro security tools. The ransomware executable (readtext34.exe, linked to the BabyLockerKZ family) disabled recovery mechanisms by deleting Volume Shadow Copies, stopped services, and used the native Windows cipher.exe utility to wipe unallocated space before encrypting files with RSA+AES. A reverse shell connected to a C2 IP associated with the BianLian Go Trojan was also launched. IOCs including file hashes, C2 IP, and ransom note contact emails are provided.

6m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundThe AttackConclusionIOCs