216.73.216.233

Hunt for RedCurl

· Published 10/01/2025 04:34 · Modified 10/01/2025 08:42

Export JSON

Essential information

Published
10/01/2025 04:34
Modified
10/01/2025 08:42
Tags
2025-01-10 cloud exfiltration cyberespionage redloader
Related entities
14 observables, 1 intrusion sets (apt), 12 techniques (mitre), 1 malware, 7 others

Description

Huntress uncovered RedCurl activity across several Canadian organizations in late 2024, tracing back to November 2023. RedCurl, known for , targets various industries to access confidential data without encrypting systems or demanding ransom. The group employs unique tactics, including the use of pcalua.exe for indirect command execution, scheduled tasks mimicking legitimate Windows processes, and Python scripts for reverse proxy tunnels. They utilize 7zip for file extraction and archiving, and leverage cloud storage for exfiltration. RedCurl's loader malware, , employs obfuscation techniques like dynamic DLL resolution and string encryption. The attackers' infrastructure included domains resolving to multiple IP addresses, showing connections to previously observed RedCurl activity.

External references