logo

RedCurl Uses New QWCrypt Ransomware in Hypervisor Attacks

ID: 1de411ff-b4ac-5463-baf0-0d7e64085e09

STIX ID: report--1de411ff-b4ac-5463-baf0-0d7e64085e09

Feed Name: HackRead

Threat Score
80/100

Date Published: 2025-03-27

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Bitdefender Labs attributes a shift in operations by RedCurl (aka Earth Kapre/Red Wolf) to the deployment of a novel ransomware family, QWCrypt, which targets hypervisors and encrypts virtual machines. The campaign leverages phishing (IMG → malicious screensaver → DLL), DLL sideloading, living-off-the-land techniques, WMI-based lateral movement, a modified wmiexec, and Chisel tunneling; it disables endpoint defenses and deploys a GO executable (rbcw.exe) using XChaCha20-Poly1305 encryption. Victims are primarily observed in the US with additional cases in Germany, Spain, Mexico (and reported instances in Russia), and the group notably avoids public leak sites, suggesting either mercenary operations or private negotiations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.