Threat group.View on attack.mitre.org
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
|
| T1005 Data from Local System |
RedCurl has collected data from the local disk of compromised hosts. |
| T1020 Automated Exfiltration |
RedCurl has used batch scripts to exfiltrate data. |
| T1027 Obfuscated Files or Information |
RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1036.005 Match Legitimate Resource Name or Location |
RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and |
| T1039 Data from Network Shared Drive |
RedCurl has collected data about network drives. |
| T1046 Network Service Discovery |
RedCurl has used netstat to check if port 4119 is open. |
| T1053.005 Scheduled Task |
RedCurl has created scheduled tasks for persistence. |
| T1056.002 GUI Input Capture |
RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. |
| T1059.001 PowerShell |
RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.003 Windows Command Shell |
RedCurl has used the Windows Command Prompt to execute commands. |
| T1059.005 Visual Basic |
RedCurl has used VBScript to run malicious files. |
| T1059.006 Python |
RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
| T1070.004 File Deletion |
RedCurl has deleted files after execution. |
| T1071.001 Web Protocols |
RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.