RedCurl

MITRE ATT&CK: G1039 View on attack.mitre.org

Aliases: RedCurl

First seen
2018-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Related IoCs
7 (7 malicious)
Last IoC activity
2025-04-19 21:22:50
Profile updated
2026-07-07 12:30:52

Targeted industries: financial-services professional-services retail-and-hospitality

Targeted regions: country_code:ua country_code:ca country_code:gb

Context

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to RedCurl (G1039). The 7 most recently updated:

TypeIndicatorUpdatedSources
hostname cv.smartapply.indeed.resumeexpert.cloud 2025-04-19 1
hostname get.indeed.resumeexpert.cloud 2025-04-19 1
hostname cvsend.resumeexpert.cloud 2025-04-19 1
hostname seek.resumeexpert.cloud 2025-04-19 1
hostname view.smartapply.resumeexpert.cloud 2025-04-19 1
hostname send.resumeexpert.cloud 2025-04-19 1
hostname check.smartapply.resumeexpert.cloud 2025-04-19 1

Detection coverage

  • 844 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Web Service (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Data from Network Shared Drive (attack-pattern)
  • Taint Shared Content (attack-pattern)
  • Malicious File (attack-pattern)
  • Data from Local System (attack-pattern)
  • Automated Collection (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • PowerShell (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Visual Basic (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Email Account (attack-pattern)
  • Malware (attack-pattern)
  • Local Account (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Malicious Link (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)

Reports & references

  • MITRE ATT&CK — G1039 (report)
  • group-ib.com — Red Curl 2 (report)
  • group-ib.com — Red Curl (report)

External references