RedCurl — APT Profile
RedCurl conducts corporate espionage against a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks; the group has been active since 2018. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.Also tracked as
Earth Kapre
Vendor research
- RedCurl: The Pentest You Didn’t Know About group-ib redcurl
- RedCurl: The Awakening group-ib redcurl