Overview 65 indicators
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.
| domain | 58 | G1039-domain.txt |
| url_path | 5 | G1039.json |
| ipv4 | 2 | G1039.json |
Techniques 41 ATT&CK
Open in ATT&CK Navigator → or download the layer (41 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1005 Data from Local System
- T1020 Automated Exfiltration
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1039 Data from Network Shared Drive
- T1046 Network Service Discovery
- T1053.005 Scheduled Task
- T1056.002 GUI Input Capture
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1080 Taint Shared Content
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1087.003 Email Account
- T1102 Web Service
- T1114.001 Local Email Collection
- T1119 Automated Collection
- T1199 Trusted Relationship
- T1202 Indirect Command Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1218.011 Rundll32
- T1537 Transfer Data to Cloud Account
- T1547.001 Registry Run Keys / Startup Folder
- T1552.001 Credentials In Files
- T1552.002 Credentials in Registry
- T1555.003 Credentials from Web Browsers
- T1560.001 Archive via Utility
- T1564.001 Hidden Files and Directories
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1587.001 Malware
Principal sources 19 reports
Ranked by how many of this actor's indicators each report brought in.
- 36twitter.com/k3yp0d/status/1710230683870785767
- 36bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f…
- 36community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10…
- 36virustotal.com/gui/ip-address/23.254.224.79/relations
- 36virustotal.com/gui/ip-address/45.61.138.81/relations
- 36virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46…
- 36virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2…
- 36virustotal.com/gui/file/4188c953d784049dbd5be209e655d6…
Timeline 65 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/SophosXOps/status/1950483325996445879
automatinghrservices.workers.dev dav.automatinghrservices.workers.dev live.airemoteplant.workers.dev quiet.msftlivecloudsrv.workers.dev -
esentire.com/blog/unraveling-the-many-stages-and-tec… · github.com/eSentire/iocs/blob/main/EarthKapre/Eart…
community.rmobileappdevelopment.workers.dev cvsend.resumeexpert.cloud datascience.iotconnectivity.workers.dev live.itsmartuniverse.workers.dev mia.nl.tab.digital sm.vbigdatasolutions.workers.dev -
x.com/birchb0y/status/1877491934639313096 · huntress.com/blog/the-hunt-for-redcurl-2
domain alphastoned.pro domain bora.teracloud.jp domain cdn.wgroadcdn.workers.dev domain mainsts-01.cn.alphastoned.pro domain sup.wgsphere.workers.dev domain wgroadcdn.workers.dev domain wgsphere.workers.dev ipv4 188.130.207.253:10310 ipv4 193.176.158.30:40141 -
x.com/SophosXOps/status/1950483325996445879
/ldn20_seek /ldn22_samsung /ldn25_cv_au -
fiona.forcloudnetworks.online -
twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020…
clever.forcloudnetworks.online ctrl1.sm.advhost.co.uk forcloudnetworks.online hfn-c-001.cc.msftcloud.click hwsrv-1048332.hostwindsdns.com ksg-c-001.cc.msftcloud.click ksg-c-002.cc.msftcloud.click ktr-cn-001.amscloudhost.com l3-dn-01.servicehost.click l4-dn-01.servicehost.click l7-dn-01.servicehost.click trur-c-001.cc.msftcloud.click -
x.com/SophosXOps/status/1950483325996445879
/ldn23_samsung -
x.com/SophosXOps/status/1950483325996445879
/ldn21_amazon -
twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020… · twitter.com/k3yp0d/status/1708495262673465713 · virustotal.com/gui/file/61ca00df551f138d3f8602c19936c4…
app-l07.servicehost.click -
twitter.com/k3yp0d/status/1710230683870785767 · bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f… · community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10… · virustotal.com/gui/ip-address/23.254.224.79/relations · virustotal.com/gui/ip-address/45.61.138.81/relations · virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46… · virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2… · virustotal.com/gui/file/4188c953d784049dbd5be209e655d6… · virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f… · virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020…
amscloudhost.com app-ins-001.amscloudhost.com app-ins-002.amscloudhost.com app-l01.msftcloud.click app-l03.msftcloud.click app-l03.servicehost.click cloud-01.servicehost.click dav.cloud-01.servicehost.click dav.linkedin-cloud-manager.servicehost.click ktr-cn-002.amscloudhost.com l-dn-01.msftcloud.click l-dn-02.msftcloud.click linkedin-cloud-manager.servicehost.click m-dn-001.amscloudhost.com m-dn-002.amscloudhost.com msftcloud.click mtk-cn-001.amscloudhost.com mtk-cn-002.amscloudhost.com rl-cn-s-001.amscloudhost.com servicehost.click ss-cn-001.amscloudhost.com ss-cn-002.amscloudhost.com test.amscloudhost.com -
community.emergingthreats.net/t/ruleset-update-summary-2023-09-08-v10…
buyhighroad.scienceontheweb.net eap.byethost10.com earthmart.c1.biz tdnmouse.atspace.eu
Further reading 22
- attack.mitre.org/groups/G1039
- group-ib.com/resources/research-hub/red-curl-2
- group-ib.com/resources/research-hub/red-curl
- huntress.com/blog/the-hunt-for-redcurl-2
- virustotal.com/gui/ip-address/45.61.138.81/relations
- virustotal.com/gui/file/4188c953d784049dbd5be209e655d6…
- virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f…
- x.com/SophosXOps/status/1950483325996445879
- virustotal.com/gui/file/8d9aaa5cf9c7b442917a8f8542d020…
- community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10…
- community.emergingthreats.net/t/ruleset-update-summary-2023-09-08-v10…
- x.com/birchb0y/status/1877491934639313096
- virustotal.com/gui/file/61ca00df551f138d3f8602c19936c4…
- bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-f…
- virustotal.com/gui/ip-address/23.254.224.79/relations
- twitter.com/k3yp0d/status/1708495262673465713
- esentire.com/blog/unraveling-the-many-stages-and-tec…
- github.com/eSentire/iocs/blob/main/EarthKapre/Eart…
- virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa2…
- facct.ru/blog/redcurl-2024
- virustotal.com/gui/file/e7b881cd106aefa6100d0e5f361e46…
- twitter.com/k3yp0d/status/1710230683870785767