← All actors Recent activity

RedCurl G1039

REDWOLF · earthkapre · goldblade · redcurl · redloader

Indicators
65
Source reports
19
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20232026

Overview 65 indicators

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

domain58G1039-domain.txt
url_path5G1039.json
ipv42G1039.json

Techniques 41 ATT&CK

Open in ATT&CK Navigator → or download the layer (41 techniques, layer 4.5)

Principal sources 19 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 65 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 4 domainthis year

    x.com/SophosXOps/status/1950483325996445879

    automatinghrservices.workers.dev
    dav.automatinghrservices.workers.dev
    live.airemoteplant.workers.dev
    quiet.msftlivecloudsrv.workers.dev

  2. 6 domain1 yr ago

    esentire.com/blog/unraveling-the-many-stages-and-tec… · github.com/eSentire/iocs/blob/main/EarthKapre/Eart…

    community.rmobileappdevelopment.workers.dev
    cvsend.resumeexpert.cloud
    datascience.iotconnectivity.workers.dev
    live.itsmartuniverse.workers.dev
    mia.nl.tab.digital
    sm.vbigdatasolutions.workers.dev

  3. 7 domain, 2 ipv41 yr ago

    x.com/birchb0y/status/1877491934639313096 · huntress.com/blog/the-hunt-for-redcurl-2

    domainalphastoned.pro
    domainbora.teracloud.jp
    domaincdn.wgroadcdn.workers.dev
    domainmainsts-01.cn.alphastoned.pro
    domainsup.wgsphere.workers.dev
    domainwgroadcdn.workers.dev
    domainwgsphere.workers.dev
    ipv4188.130.207.253:10310
    ipv4193.176.158.30:40141

  4. 3 url_path2 yrs ago

    x.com/SophosXOps/status/1950483325996445879

    /ldn20_seek
    /ldn22_samsung
    /ldn25_cv_au

  5. 1 domain2 yrs ago

    facct.ru/blog/redcurl-2024

    fiona.forcloudnetworks.online

  6. 12 domain3 yrs ago

    twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020…

    clever.forcloudnetworks.online
    ctrl1.sm.advhost.co.uk
    forcloudnetworks.online
    hfn-c-001.cc.msftcloud.click
    hwsrv-1048332.hostwindsdns.com
    ksg-c-001.cc.msftcloud.click
    ksg-c-002.cc.msftcloud.click
    ktr-cn-001.amscloudhost.com
    l3-dn-01.servicehost.click
    l4-dn-01.servicehost.click
    l7-dn-01.servicehost.click
    trur-c-001.cc.msftcloud.click

  7. 1 url_path3 yrs ago

    x.com/SophosXOps/status/1950483325996445879

    /ldn23_samsung

  8. 1 url_path3 yrs ago

    x.com/SophosXOps/status/1950483325996445879

    /ldn21_amazon

  9. 1 domain3 yrs ago

    twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020… · twitter.com/k3yp0d/status/1708495262673465713 · virustotal.com/gui/file/61ca00df551f138d3f8602c19936c4…

    app-l07.servicehost.click

  10. 23 domain3 yrs ago

    twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020…

    amscloudhost.com
    app-ins-001.amscloudhost.com
    app-ins-002.amscloudhost.com
    app-l01.msftcloud.click
    app-l03.msftcloud.click
    app-l03.servicehost.click
    cloud-01.servicehost.click
    dav.cloud-01.servicehost.click
    dav.linkedin-cloud-manager.servicehost.click
    ktr-cn-002.amscloudhost.com
    l-dn-01.msftcloud.click
    l-dn-02.msftcloud.click
    linkedin-cloud-manager.servicehost.click
    m-dn-001.amscloudhost.com
    m-dn-002.amscloudhost.com
    msftcloud.click
    mtk-cn-001.amscloudhost.com
    mtk-cn-002.amscloudhost.com
    rl-cn-s-001.amscloudhost.com
    servicehost.click
    ss-cn-001.amscloudhost.com
    ss-cn-002.amscloudhost.com
    test.amscloudhost.com

  11. 4 domain3 yrs ago

    community.emergingthreats.net/t/ruleset-update-summary-2023-09-08-v10…

    buyhighroad.scienceontheweb.net
    eap.byethost10.com
    earthmart.c1.biz
    tdnmouse.atspace.eu

Further reading 22