RedCurl
MITRE ATT&CK: G1039 View on attack.mitre.org
Aliases: RedCurl
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Related IoCs
- 7 (7 malicious)
- Last IoC activity
- 2025-04-19 21:22:50
- Profile updated
- 2026-07-07 12:30:52
Targeted industries: financial-services professional-services retail-and-hospitality
Targeted regions: country_code:ua country_code:ca country_code:gb
Context
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to RedCurl (G1039). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | cv.smartapply.indeed.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | get.indeed.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | cvsend.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | seek.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | view.smartapply.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | send.resumeexpert.cloud | 2025-04-19 | 1 |
| hostname | check.smartapply.resumeexpert.cloud | 2025-04-19 | 1 |
Detection coverage
- 844 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Web Service (attack-pattern)
- Local Email Collection (attack-pattern)
- Data from Network Shared Drive (attack-pattern)
- Taint Shared Content (attack-pattern)
- Malicious File (attack-pattern)
- Data from Local System (attack-pattern)
- Automated Collection (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- PowerShell (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Visual Basic (attack-pattern)
- Archive via Utility (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- Email Account (attack-pattern)
- Malware (attack-pattern)
- Local Account (attack-pattern)
- GUI Input Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Malicious Link (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
Reports & references
- MITRE ATT&CK — G1039 (report)
- group-ib.com — Red Curl 2 (report)
- group-ib.com — Red Curl (report)