ATT&CKReferencestrendmicro_redcurl

trendmicro_redcurl

Tancio et al. (2024, March 6). Unveiling Earth Kapre aka RedCurl’s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence. Retrieved August 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1046
Network Service Discovery
GroupRedCurl

RedCurl has used netstat to check if port 4119 is open.

T1053.005
Scheduled Task
GroupRedCurl

RedCurl has created scheduled tasks for persistence.

T1059.001
PowerShell
GroupRedCurl

RedCurl has used PowerShell to execute commands and to download malware.

T1059.003
Windows Command Shell
GroupRedCurl

RedCurl has used the Windows Command Prompt to execute commands.

T1059.006
Python
GroupRedCurl

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

T1070.004
File Deletion
GroupRedCurl

RedCurl has deleted files after execution.

T1202
Indirect Command Execution
GroupRedCurl

RedCurl has used pcalua.exe to obfuscate binary execution and remote connections.

T1204.002
Malicious File
GroupRedCurl

RedCurl has used malicious files to infect the victim machines.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1560.001
Archive via Utility
GroupRedCurl

RedCurl has downloaded 7-Zip to decompress password protected archives.

T1566.001
Spearphishing Attachment
GroupRedCurl

RedCurl has used phishing emails with malicious files to gain initial access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.