RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment
For the first time, a ransomware campaign has been connected to the Russian-speaking hacker collective RedCurl, which represents a shift in the threat actor's tactics.
The action, which was noticed by the Romanian cybersecurity firm Bitdefender, entails the use of a ransomware strain called QWCrypt that has never been seen before.
RedCurl, also known as Earth Kapre and Red Wolf, has a track record of planning corporate espionage attacks against organizations in the US, UK, Canada, Germany, Norway, Russia, Slovenia, and Ukraine. Since at least November 2018, it has been known to be active.
In 2020, Group-IB revealed attack chains that used spear-phishing emails with lures related to human resources (HR) to initiate the malware distribution process. Huntress described the threat ac...

