Tancio et al. (2024, March 6). Unveiling Earth Kapre aka RedCurl’s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence. Retrieved August 9, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupRedCurl | RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1046 Network Service Discovery |
GroupRedCurl | RedCurl has used netstat to check if port 4119 is open. |
| T1053.005 Scheduled Task |
GroupRedCurl | RedCurl has created scheduled tasks for persistence. |
| T1059.001 PowerShell |
GroupRedCurl | RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.003 Windows Command Shell |
GroupRedCurl | RedCurl has used the Windows Command Prompt to execute commands. |
| T1059.006 Python |
GroupRedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
| T1070.004 File Deletion |
GroupRedCurl | RedCurl has deleted files after execution. |
| T1202 Indirect Command Execution |
GroupRedCurl | RedCurl has used pcalua.exe to obfuscate binary execution and remote connections. |
| T1204.002 Malicious File |
GroupRedCurl | RedCurl has used malicious files to infect the victim machines. |
| T1218.011 Rundll32 |
GroupRedCurl | RedCurl has used rundll32.exe to execute malicious files. |
| T1560.001 Archive via Utility |
GroupRedCurl | RedCurl has downloaded 7-Zip to decompress password protected archives. |
| T1566.001 Spearphishing Attachment |
GroupRedCurl | RedCurl has used phishing emails with malicious files to gain initial access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.