Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedCurl

Also known as: RedCurl, Red Wolf, GOLD BLADE

Description

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks.(Citation: group-ib_redcurl1) RedCurl is allegedly a Russian-speaking threat actor.(Citation: group-ib_redcurl1)(Citation: group-ib_redcurl2) The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

AI Analysis

· 1 week ago

Executive Summary

RedCurl is a cyber threat actor active since 2018, notable for conducting corporate espionage activities targeting industries such as travel agencies, insurance companies, and banks across regions including Ukraine, Canada, and the United Kingdom. The group primarily uses spearphishing campaigns to gain initial access, followed by data discovery and exfiltration through scripts and commands. RedCurl is suspected to be Russian-speaking, with a focus on stealing sensitive corporate information.

Goals & Targeting

RedCurl's primary objectives appear to be corporate espionage and the theft of sensitive business information, intellectual property, and financial data from targeted industries. The group's focus on sectors like banking, insurance, and travel suggests a strategic interest in economic gain through stolen data or disruptions. The targeting of countries like Ukraine, Canada, and the UK may indicate geopolitical motives or alignment with interests in those regions.

Enhanced Description

RedCurl operates as a cyber espionage group targeting various sectors globally. The group employs sophisticated tactics to breach organizations, beginning with spearphishing emails to gain initial access. Once inside, the actors execute scripts and commands to discover corporate data, which is then exfiltrated to their command-and-control (C2) servers. RedCurl's operations demonstrate a high level of technical skill, including the use of encryption and obfuscation techniques to avoid detection. The group's targeting scope and consistent activity over multiple years suggest either a well-organized single-cell group or part of a larger threat network.

Key Capabilities

  • Spearphishing campaigns targeting corporate employees
  • Use of scripts and commands for data discovery
  • Encrypted communication channels for C2
  • Exfiltration of sensitive corporate information
  • Obfuscation techniques to avoid detection

MITRE ATT&CK Tactics

Discovery
Lateral Movement
Exfiltration
Credential Access
Encryption
Obfuscation

ATT&CK Techniques

T1053.005
T1560.001
T1087.002
T1036.005
T1114.001
T1587.001
T1204.002
T1080
T1573.001
T1566.001
T1566.002
T1119
T1552.002
T1202
T1087.003
T1005
T1087.001
T1020
T1083
T1102
T1059.001
T1119
T1552.001
T1547.001
T1056.002
T1537
T1059.005

Software / Tooling

Spearphishing tools (unknown)
Scripting tools (unknown)
Encrypted C2 channels
Cobalt Strike (suspected)
Mimikatz-like toolset (speculated)

Campaigns & Victims

RedCurl's campaigns typically involve long-term access to target networks, with a focus on data collection and exfiltration. The group appears to target organizations in the travel, insurance, and banking sectors globally. While no specific campaign names are linked to RedCurl, their operational consistency suggests potential economic or geopolitical motivations. The actor's persistence over multiple years indicates a dedicated effort to gather intelligence on targeted industries.

IOC Patterns

  • Spearphishing emails with malicious links or attachments
  • Scheduled task persistence mechanisms
  • Encrypted communication channels for C2
  • Obfuscated files or information storage
  • File and directory discovery through scripts

Recommended Actions

  • Implement email filtering to detect spearphishing attempts
  • Monitor for unusual script activity on network endpoints
  • Enhance credentials protection measures (e.g., MFA)
  • Regularly review scheduled task listings for anomalies
  • Enforce strict controls over data exfiltration channels

Suggested Tags

Corporate Espionage
Economic Espionage
Banking Sector
Insurance Sector
Travel Sector
Russian-Speaking Actor

Confidence Assessment

Confidence in RedCurl's TTPs and goals is moderate based on available data from Group-IB, but specific campaign details and direct evidence of their activities remain limited. A potential gap exists in identifying the exact tools they use and their long-term strategic goals beyond immediate data theft.

ATT&CK Techniques

Collection
6 techniques
Discovery
6 techniques
Execution
7 techniques
Stealth
6 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. group-ib_redcurl1 — Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024.
  2. group-ib_redcurl2 — Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024.

Intel Summary

41

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Corporate Espionage
Economic Espionage
Banking Sector
Insurance Sector
Travel Sector
Russian-Speaking Actor

Details

MITRE ID
G1039
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--82323c70-4186-4b61-94f5-b227c3b28e89
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.