Tag: STAC6565

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware
News

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

A targeted cyber campaign led by a threat activity cluster called STAC6565 has turned its attention to Canadian organizations. Sophos, a cybersecurity firm, reported that between February 2024 and August 2025, it looked at nearly forty intrusions connected to the threat actor. The effort is highly likely to have overlaps with the hacker group Gold Blade, which is also monitored under the aliases Earth Kapre, RedCurl, and Red Wolf. The financially motivated threat actor is thought to have been active since late 2018, first focusing on Russian organizations before moving on to Canada, Germany, Norway, Russia, Slovenia, Ukraine, the United Kingdom, and the United States. The group has a track record of conducting commercial espionage using phishing emails. RedCurl, however, has been...