STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

A targeted cyber campaign led by a threat activity cluster called STAC6565 has turned its attention to Canadian organizations.

Sophos, a cybersecurity firm, reported that between February 2024 and August 2025, it looked at nearly forty intrusions connected to the threat actor. The effort is highly likely to have overlaps with the hacker group Gold Blade, which is also monitored under the aliases Earth Kapre, RedCurl, and Red Wolf.

The financially motivated threat actor is thought to have been active since late 2018, first focusing on Russian organizations before moving on to Canada, Germany, Norway, Russia, Slovenia, Ukraine, the United Kingdom, and the United States. The group has a track record of conducting commercial espionage using phishing emails.

RedCurl, however, has been implicated in ransomware attacks employing a custom malware strain known as QWCrypt read more about STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *