RedCurl

G1039

Threat group.View on attack.mitre.org

About this group

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

Techniques used41

Procedure examples41

TechniqueProcedure example
T1003.001
LSASS Memory

RedCurl used LaZagne to obtain passwords from memory.

T1005
Data from Local System

RedCurl has collected data from the local disk of compromised hosts.

T1020
Automated Exfiltration

RedCurl has used batch scripts to exfiltrate data.

T1027
Obfuscated Files or Information

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1036.005
Match Legitimate Resource Name or Location

RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and
`MdMMaintenenceTask` to mask malicious files and scheduled tasks.

T1039
Data from Network Shared Drive

RedCurl has collected data about network drives.

T1046
Network Service Discovery

RedCurl has used netstat to check if port 4119 is open.

T1053.005
Scheduled Task

RedCurl has created scheduled tasks for persistence.

T1056.002
GUI Input Capture

RedCurl prompts the user for credentials through a Microsoft Outlook pop-up.

T1059.001
PowerShell

RedCurl has used PowerShell to execute commands and to download malware.

T1059.003
Windows Command Shell

RedCurl has used the Windows Command Prompt to execute commands.

T1059.005
Visual Basic

RedCurl has used VBScript to run malicious files.

T1059.006
Python

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

T1070.004
File Deletion

RedCurl has deleted files after execution.

T1071.001
Web Protocols

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

View all 41 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References2

  1. group-ib_redcurl1 Open source
    Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024.
  2. group-ib_redcurl2 Open source
    Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.