Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Red Canary, a Zscaler company

Red Canary, a Zscaler company Vendor Cyber Rating & Cyber Score

redcanary.com

Red Canary stops cyber threats no one else does, so organizations can fearlessly pursue their missions. Security leaders all share one goal: ‘Don’t get breached.’ Since day one at Red Canary, enterprises have relied on us to find and stop threats before they can cause harm. The most sophisticated security teams trust us for our intelligence-led Security Operations platform run by world-class security experts.  We manage, detect and respond to prevalent threats across cloud, identity and endpoint so you can have more time to focus on business-specific specific security needs and requirements.  We got you.


RCZC A.I CyberSecurity Scoring

RCZC
Company Information
Website:https://redcanary.com/
Employees number:404
Number of followers:77,986
NAICS:541514
Industry Type:Computer and Network Security
Homepage:redcanary.com
RCZC Risk Score (AI oriented)
Between 650 and 699
logo
RCZCComputer and Network Security
Updated:
04/04/2026
668/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RCZC Global Score (TPRM)
xxxx
logo
RCZCComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RCZC
RCZCWeak
Current Score
668B (WEAK)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
672Before Incident
MAY 2026
670Before Incident
APRIL 2026
669Before Incident
MARCH 2026
666Before Incident
FEBRUARY 2026
664Before Incident
JANUARY 2026
662Before Incident
DECEMBER 2025
661Before Incident
NOVEMBER 2025
678Before Incident
Cyber Attack
01 Nov 2025RCZC
Huntress, Rhysida and Expel: Gootloader Malware Maintains Low Detection Rate While Bypassing Most Security Tools

Gootloader’s Sophisticated Anti-Detection Tactics Exposed in Latest Campaign

657After Incident
LOW-21
HUNREDEXP1768977371
Gootloader’s Sophisticated Anti-Detection Tactics Exposed in Latest Campaign A recent analysis by Huntress and Expel reveals how the Gootloader malware leverages deliberately malformed ZIP archives to evade security tools while maintaining functionality for targeted victims. The threat actor, known for its role as an initial access broker in ransomware operations, has partnered with Vanilla Tempest, a group deploying Rhysida ransomware, in an ongoing campaign active since November 2025. ### Evasion Through Malformed ZIP Archives Gootloader’s infection chain begins with weaponized ZIP files containing malicious JScript payloads, such as "Indiana_Animal_Protection_Laws_Guide.js." These archives are engineered to bypass analysis tools like 7-Zip and WinRAR while remaining extractable via Windows’ native unarchiving utility. Key evasion techniques include: - Concatenated ZIP structures: Each archive contains 500–1,000 nested ZIP files, with the End of Central Directory (EOCD) record strategically placed to direct extraction to the valid payload. - Truncated EOCD records: Missing critical bytes violate ZIP format standards, causing parsing failures in security tools. - Randomized metadata: Mismatched version numbers, timestamps, CRC32 checksums, and file sizes between local file headers and central directory records further disrupt analysis. - Client-side generation: Victims receive XOR-encoded data blobs decoded by browsers, assembling into identical ZIP structures until reaching 70–80 MB despite the extracted JScript payload being only ~287 KB. ### Execution & Persistence When victims extract and run the JScript file, Windows Script Host (WScript) processes it from `AppData\Local\Temp`, initiating a multi-stage attack: 1. Persistence: Creates LNK shortcuts in the Startup folder, referencing secondary scripts via NTFS short filenames (e.g., `FILENA~1.js`). 2. Obfuscated PowerShell execution: CScript launches the script, which spawns PowerShell processes with heavily obfuscated commands to establish command-and-control (C2) communications. ### Detection & Indicators of Compromise Security teams can identify Gootloader activity by monitoring: - Process patterns: `wscript.exe` executing JScript from temp directories, followed by `cscript.exe` invoking scripts via NTFS shortnames and spawning PowerShell. - File characteristics: ZIP archives with >100 instances of `PK\x03\x04` (local file headers) or `PK\x05\x06` (EOCD records). - Persistence artifacts: LNK files in `\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\`. Known IOCs: - File hash (SHA-256): `b05eb7a367b5b86f8527af7b14e97b311580a8ff73f27eaa1fb793abb902dc6e` - Malicious extensions: `.js`, `.jse` - Execution paths: Temp directories, NTFS shortname scripts Gootloader remains a persistent threat, historically accounting for 11% of malware bypassing enterprise security solutions. Its collaboration with Vanilla Tempest underscores its role in facilitating Rhysida ransomware attacks.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Initial access for ransomware operations (Rhysida ransomware deployment)
DATA BREACH
.js.jse
OCTOBER 2025
678Before Incident
SEPTEMBER 2025
676Before Incident
AUGUST 2025
674Before Incident
JULY 2025
673Before Incident
JUNE 2024
755Before Incident
Ransomware
01 Jun 2024RCZC
Rhysida and Vidar: OysterLoader Multi‑Stage Evasion Loader Uncovered with Advanced Obfuscation and Rhysida Ransomware Links

OysterLoader: A Sophisticated Malware Threat Delivering Ransomware and Infostealers

646After Incident
CRITICAL-109
VIDRED1770978271
OysterLoader: A Sophisticated Malware Threat Delivering Ransomware and Infostealers A newly identified malware loader, OysterLoader, has emerged as a major cybersecurity threat, leveraging advanced obfuscation techniques to evade detection and deploy malicious payloads. First detected in June 2024 by Rapid7, this C++-based malware spreads through fake websites impersonating trusted software like PuTTY, WinSCP, Google Authenticator, and AI tools, often disguised as digitally signed Microsoft Installer (MSI) files to appear legitimate. OysterLoader operates through a four-stage infection chain, beginning with a TextShell packer and progressing to custom shellcode execution before delivering its final payload. While primarily linked to Rhysida ransomware a group tied to the WIZARD SPIDER threat actor it has also been observed distributing Vidar, a prevalent infostealer as of January 2026. Security researchers, including Sekoia analysts, have identified a two-tiered command-and-control (C2) infrastructure, with delivery servers handling initial connections and final C2 servers managing victim interactions. The malware employs anti-analysis techniques, such as API hammering, dynamic API resolution via custom hashing, and timing-based sandbox detection, to evade security measures. ### Advanced Evasion and Persistence Mechanisms OysterLoader’s infection process demonstrates high technical sophistication, including: - Environment checks to ensure the target system has at least 60 running processes before proceeding. - Steganography to conceal payloads within icon image files, using RC4 encryption with a hardcoded key. - Custom JSON encoding with a non-standard Base64 alphabet and random shift values, complicating network traffic analysis. - Persistence via scheduled tasks that execute a malicious DLL in the AppData directory every 13 minutes. The malware’s developers have continuously updated its code, refining communication protocols and obfuscation to maintain effectiveness against security solutions. Its connection to Rhysida ransomware and commodity malware underscores its role in high-impact cyberattacks, making it a critical concern for organizations.
INCIDENT DETAILS -
TYPE
MalwareRansomwareInfostealer
MOTIVATION
Financial gainData theft
DATA BREACH
Personally identifiable informationPayment informationCredentialsSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RCZC ?
?
What was RCZC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RCZC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RCZC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RCZC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RCZC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RCZC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RCZC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RCZC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RCZC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was RCZC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was RCZC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on RCZC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RCZC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RCZC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?