ATT&CKReferencesgroup-ib_redcurl2

group-ib_redcurl2

Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupRedCurl

RedCurl used LaZagne to obtain passwords from memory.

T1005
Data from Local System
GroupRedCurl

RedCurl has collected data from the local disk of compromised hosts.

T1020
Automated Exfiltration
GroupRedCurl

RedCurl has used batch scripts to exfiltrate data.

T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1036.005
Match Legitimate Resource Name or Location
GroupRedCurl

RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and
`MdMMaintenenceTask` to mask malicious files and scheduled tasks.

T1039
Data from Network Shared Drive
GroupRedCurl

RedCurl has collected data about network drives.

T1053.005
Scheduled Task
GroupRedCurl

RedCurl has created scheduled tasks for persistence.

T1056.002
GUI Input Capture
GroupRedCurl

RedCurl prompts the user for credentials through a Microsoft Outlook pop-up.

T1059.001
PowerShell
GroupRedCurl

RedCurl has used PowerShell to execute commands and to download malware.

T1059.003
Windows Command Shell
GroupRedCurl

RedCurl has used the Windows Command Prompt to execute commands.

T1059.005
Visual Basic
GroupRedCurl

RedCurl has used VBScript to run malicious files.

T1070.004
File Deletion
GroupRedCurl

RedCurl has deleted files after execution.

T1071.001
Web Protocols
GroupRedCurl

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

T1080
Taint Shared Content
GroupRedCurl

RedCurl has placed modified LNK files on network drives for lateral movement.

T1082
System Information Discovery
GroupRedCurl

RedCurl has collected information about the target system, such as system information and list of network connections.

T1083
File and Directory Discovery
GroupRedCurl

RedCurl has searched for and collected files on local and network drives.

T1087.001
Local Account
GroupRedCurl

RedCurl has collected information about local accounts.

T1087.002
Domain Account
GroupRedCurl

RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality .

T1087.003
Email Account
GroupRedCurl

RedCurl has collected information about email accounts.

T1102
Web Service
GroupRedCurl

RedCurl has used web services to download malicious files.

T1119
Automated Collection
GroupRedCurl

RedCurl has used batch scripts to collect data.

T1204.001
Malicious Link
GroupRedCurl

RedCurl has used malicious links to infect the victim machines.

T1204.002
Malicious File
GroupRedCurl

RedCurl has used malicious files to infect the victim machines.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1537
Transfer Data to Cloud Account
GroupRedCurl

RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service.

T1547.001
Registry Run Keys / Startup Folder
GroupRedCurl

RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1552.001
Credentials In Files
GroupRedCurl

RedCurl used LaZagne to obtain passwords in files.

T1552.002
Credentials in Registry
GroupRedCurl

RedCurl used LaZagne to obtain passwords in the Registry.

T1555.003
Credentials from Web Browsers
GroupRedCurl

RedCurl used LaZagne to obtain passwords from web browsers.

T1564.001
Hidden Files and Directories
GroupRedCurl

RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files.

T1566.002
Spearphishing Link
GroupRedCurl

RedCurl has used phishing emails with malicious links to gain initial access.

T1573.001
Symmetric Cryptography
GroupRedCurl

RedCurl has used AES-128 CBC to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
GroupRedCurl

RedCurl has used HTTPS for C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.