ATT&CKReferencestherecord_redcurl

therecord_redcurl

Antoniuk, D. (2023, July 17). RedCurl hackers return to spy on 'major Russian bank,' Australian company. Retrieved August 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1083
File and Directory Discovery
GroupRedCurl

RedCurl has searched for and collected files on local and network drives.

T1199
Trusted Relationship
GroupRedCurl

RedCurl has gained access to a contractor to pivot to the victim’s infrastructure.

T1587.001
Malware
GroupRedCurl

RedCurl has created its own tools to use during operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.