RedCurl

First seen
2019-07-01 00:00:00
Malware type
spyware, trojan
Family
Malware family
Profile updated
2026-07-07 15:17:41

Targeted industries: professional-services retail-and-hospitality energy-and-utilities

Targeted regions: country_code:ru country_code:ua country_code:gb

Context

RedCurl is a known cyber-espionage group that operates in multiple sectors, conducting corporate espionage through phishing campaigns and data theft. It predominantly targets companies in Russia and Europe.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Redcurl_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Redcurl (report)
  • bi.zone — Red Wolf Vnov Shpionit Za Kommercheskimi Organizatsiyami (report)
  • go.group-ib.com — Report Redcurl En (report)
  • go.group-ib.com — Report Redcurl Awakening En (report)

External references