logo

Threat Actor RedCurl Develops Ransomware to Encrypt Hyper-V Servers

ID: bd4a2196-3c47-5ecf-928f-ad863a85b601

STIX ID: report--bd4a2196-3c47-5ecf-928f-ad863a85b601

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-03-26

Date Updated: 2026-04-28

...
...

RedCurl, an espionage-focused threat actor active since 2018, has been observed deploying a new ransomware family called QWCrypt that targets Microsoft Hyper-V VMs; researchers detail a phishing-led chain using .IMG CV attachments, DLL sideloading, scheduled tasks for persistence, bespoke lateral movement tools, and tunneling via Chisel, and note QWCrypt's XChaCha20-Poly1305 encryption, selective encryption options, and operational tradecraft suggesting stealthy, possibly state-linked motives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.