Epsilon Red is a Windows ransomware family first publicly identified in 2021. The malware is notable for separating its intrusion workflow into a lightweight Go-based encryptor and a larger set of PowerShell scripts that handle most operational tasks. In observed intrusions, attackers used a hand-operated approach, likely gaining initial access through an unpatched Microsoft Exchange server, then using WMI to deploy tooling across reachable systems. The operation relied heavily on scheduled tasks and PowerShell orchestration to prepare hosts for encryption.
Its preparatory scripts perform extensive defense evasion and pre-encryption actions, including deleting shadow copies, clearing event logs, attempting to uninstall or disable security products, terminating processes and services that could interfere with encryption, and modifying firewall rules while preserving remote administrative access. Associated activity has also included installation of remote administration software and Tor Browser, indicating interactive post-compromise control. One observed script set included functionality consistent with copying credential material from shadow copies, supporting credential access during the intrusion lifecycle.
The ransomware payload itself is a 64-bit Go executable, packed and comparatively minimal, with directory-walking and parallelized encryption logic. It broadly encrypts files, appends a distinctive extension, and drops ransom notes whose styling resembles REvil, although no strong technical overlap beyond note presentation has been established. Epsilon Red has been associated with attacks against at least a U.S. hospitality victim and with later social-engineering delivery activity using ClickFix-style lure pages that execute Windows commands to download and run payloads. Those campaigns indicate continued use against Windows environments through web-based lures and staged execution.
Epsilon Red is best characterized as a ransomware family used in manually operated intrusions that combine script-driven environment preparation, defense evasion, and interactive operator control before file encryption and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sophos analysts uncovered a new ransomware written in the Go programming language that calls itself Epsilon Red. ... The ransomware itself, called RED.exe, is a 64-bit Windows executable programmed in the Go language...
15 distinct techniques documented for this family, organized by ATT&CK tactic.
"From that machine, the attackers used WMI to install other software onto machines inside the network..." and "RED.ps1 ... was executed on the target machines using WMI."
"The PowerShell scripts also use a rudimentary form of obfuscation... added in some square brackets and braces... then use a command that strips out those brackets."
"The ransomware then ... encrypts each subfolder separately..." and "After it encrypts each file, it appends a file suffix of '.epsilonred'"
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bare-bones ransomware that relies heavily on PowerShell scripts for functionality.
Ransomware referenced as being distributed via Discord spoofing.
Ransomware first identified in 2021; leaves a ransom note resembling REvil’s (with minor grammatical improvements). Reported spread via ClickFix-like lures that trick users into downloading malicious HTA files under a CAPTCHA pretext.
Ransomware delivered via ClickFix campaigns, encrypts files and demands ransom.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.