---
title: "ReadText34 Ransomware Incident"
url: https://daily.dev/posts/readtext34-ransomware-incident-ffhzgomw8
source_url: https://www.huntress.com/blog/readtext34-ransomware-incident
type: article
source: "Huntress Blog"
published: 2026-05-31T07:42:55.758Z
updated: 2026-05-31T08:09:52.876Z
tags: ["security", "malware", "ransomware"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ReadText34 Ransomware Incident

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 6 min read · 0 upvotes · 0 comments

## Summary

A detailed incident report covering a ReadText34 ransomware attack observed by Huntress analysts in September 2024. The threat actor gained initial access using stolen Administrator credentials, enabled RDP remotely, then deployed TrueSightKiller (a known vulnerable driver) via a BYOVD technique to crash Trend Micro security tools. The ransomware executable (readtext34.exe, linked to the BabyLockerKZ family) disabled recovery mechanisms by deleting Volume Shadow Copies, stopped services, and used the native Windows cipher.exe utility to wipe unallocated space before encrypting files with RSA+AES. A reverse shell connected to a C2 IP associated with the BianLian Go Trojan was also launched. IOCs including file hashes, C2 IP, and ransom note contact emails are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/readtext34-ransomware-incident>

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/readtext34-ransomware-incident-ffhzgomw8)
