RedCurl Uses New QWCrypt Ransomware in Hypervisor Attacks
ID: 1de411ff-b4ac-5463-baf0-0d7e64085e09
STIX ID: report--1de411ff-b4ac-5463-baf0-0d7e64085e09
Feed Name: HackRead
Bitdefender Labs attributes a shift in operations by RedCurl (aka Earth Kapre/Red Wolf) to the deployment of a novel ransomware family, QWCrypt, which targets hypervisors and encrypts virtual machines. The campaign leverages phishing (IMG → malicious screensaver → DLL), DLL sideloading, living-off-the-land techniques, WMI-based lateral movement, a modified wmiexec, and Chisel tunneling; it disables endpoint defenses and deploys a GO executable (rbcw.exe) using XChaCha20-Poly1305 encryption. Victims are primarily observed in the US with additional cases in Germany, Spain, Mexico (and reported instances in Russia), and the group notably avoids public leak sites, suggesting either mercenary operations or private negotiations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
