NEW: Group Profiler — instant APT intel lookup. Try it →

RedCurl

Overview

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

Naming & attribution

RedCurl is tracked under 1 names across the industry. It uses 41 documented ATT&CK techniques — more than 76% of the 174 groups tracked here. Activity attributed since 2018.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1056.002 GUI Input Capture — used by 2 of 174 groups
  • T1202 Indirect Command Execution — used by 2 of 174 groups
  • T1537 Transfer Data to Cloud Account — used by 3 of 174 groups
  • T1552.002 Credentials in Registry — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • BRONZE BUTLER China — 19 shared techniques (31% overlap)
  • APT3 China — 17 shared techniques (25% overlap)
  • Mustang Panda China — 24 shared techniques (24% overlap)
  • MuddyWater Iran — 21 shared techniques (24% overlap)
  • Patchwork — 16 shared techniques (24% overlap)
  • APT33 Iran — 14 shared techniques (24% overlap)

TTPs — 41 techniques across 11 tactics

Resource Development

Initial Access

Execution

Persistence

Credential Access

Lateral Movement

Command and Control

Reporting (2)