logo

Hunt for RedCurl | Huntress

ID: 253bacc4-1bcf-5645-9088-7ed44d3d12ae

STIX ID: report--253bacc4-1bcf-5645-9088-7ed44d3d12ae

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2025-01-09

Date Updated: 2026-04-28

...
...

Huntress observed multiple Canada-based intrusions attributed to the RedCurl APT that used pcalua.exe scheduled tasks to execute a RedLoader backdoor and Python RPivot reverse-proxy, relied heavily on 7zip for password-protected archiving and exfiltration to cloud storage (bora.teracloud.jp), and provided IOCs, MITRE mappings, and hunting/detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.