Also known as: RedCurl, Red Wolf, GOLD BLADE
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks.(Citation: group-ib_redcurl1) RedCurl is allegedly a Russian-speaking threat actor.(Citation: group-ib_redcurl1)(Citation: group-ib_redcurl2) The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.
Executive Summary
RedCurl is a cyber threat actor active since 2018, notable for conducting corporate espionage activities targeting industries such as travel agencies, insurance companies, and banks across regions including Ukraine, Canada, and the United Kingdom. The group primarily uses spearphishing campaigns to gain initial access, followed by data discovery and exfiltration through scripts and commands. RedCurl is suspected to be Russian-speaking, with a focus on stealing sensitive corporate information.
Goals & Targeting
RedCurl's primary objectives appear to be corporate espionage and the theft of sensitive business information, intellectual property, and financial data from targeted industries. The group's focus on sectors like banking, insurance, and travel suggests a strategic interest in economic gain through stolen data or disruptions. The targeting of countries like Ukraine, Canada, and the UK may indicate geopolitical motives or alignment with interests in those regions.
Enhanced Description
RedCurl operates as a cyber espionage group targeting various sectors globally. The group employs sophisticated tactics to breach organizations, beginning with spearphishing emails to gain initial access. Once inside, the actors execute scripts and commands to discover corporate data, which is then exfiltrated to their command-and-control (C2) servers. RedCurl's operations demonstrate a high level of technical skill, including the use of encryption and obfuscation techniques to avoid detection. The group's targeting scope and consistent activity over multiple years suggest either a well-organized single-cell group or part of a larger threat network.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedCurl's campaigns typically involve long-term access to target networks, with a focus on data collection and exfiltration. The group appears to target organizations in the travel, insurance, and banking sectors globally. While no specific campaign names are linked to RedCurl, their operational consistency suggests potential economic or geopolitical motivations. The actor's persistence over multiple years indicates a dedicated effort to gather intelligence on targeted industries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in RedCurl's TTPs and goals is moderate based on available data from Group-IB, but specific campaign details and direct evidence of their activities remain limited. A potential gap exists in identifying the exact tools they use and their long-term strategic goals beyond immediate data theft.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
41
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
11
Tactics