RedDot is a ransomware family referenced in Splunk detection content as using multiple post-compromise behaviors on Windows systems. The content associates RedDot with enabling Windows firewall network discovery via netsh to discover and compromise additional machines on the network, supporting lateral movement and potentially wider file encryption across multiple hosts. It is also associated with recursive directory deletion using cmd.exe with rd /s /q, including deletion of files or directories such as recycle bin contents to prevent recovery, and with malicious script execution via cscript.exe using the JScript.Encode COM CLSID, a technique that may be used to execute arbitrary code, evade detection, maintain persistence, and potentially disable AMSI. The provided content does not name a specific threat actor operating RedDot, but it consistently characterizes it as ransomware affecting Windows environments and highlights process-level behaviors detectable through EDR, Sysmon Event ID 1, and Windows Security Event ID 4688 telemetry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The following analytic detects the execution of JavaScript using the JScript.Encode CLSID (COM Object) by cscript.exe... This activity is significant as it is a known technique used by ransomware, such as Reddot, to execute malicious scripts and potentially disable AMSI (Antimalware Scan Interface).
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reddot is referenced as ransomware that uses JScript COM CLSID execution via cscript.exe to run malicious scripts and potentially disable AMSI, enabling arbitrary code execution, evasion, and persistence.
Ransomware referenced as using firewall modification to enable network discovery in order to discover and compromise additional machines on the network, potentially leading to widespread file encryption across multiple hosts.
Ransomware referenced as using recursive batch deletion commands to delete files in the recycle bin and hinder recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.