Threat Actor RedCurl Develops Ransomware to Encrypt Hyper-V Servers
ID: bd4a2196-3c47-5ecf-928f-ad863a85b601
STIX ID: report--bd4a2196-3c47-5ecf-928f-ad863a85b601
Feed Name: Halcyon Blog
RedCurl, an espionage-focused threat actor active since 2018, has been observed deploying a new ransomware family called QWCrypt that targets Microsoft Hyper-V VMs; researchers detail a phishing-led chain using .IMG CV attachments, DLL sideloading, scheduled tasks for persistence, bespoke lateral movement tools, and tunneling via Chisel, and note QWCrypt's XChaCha20-Poly1305 encryption, selective encryption options, and operational tradecraft suggesting stealthy, possibly state-linked motives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
