logo

RedCurl Cybercrime Group Abuses Windows PCA Tool for Corporate Espionage

ID: 2bdb7958-56f0-505c-9bb5-fc61c37996b0

STIX ID: report--2bdb7958-56f0-505c-9bb5-fc61c37996b0

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-03-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes RedCurl (Earth Kapre) conducting multi-stage phishing campaigns that deliver malicious ISO/IMG attachments to fetch legitimate curl, load malicious DLLs (ms.dll/ps.dll), and abuse the Windows Program Compatibility Assistant (pcalua.exe), PowerShell, and Impacket to spawn downloaders and connect to C2 infrastructure; the report also notes Turla’s use of a Pelmeni wrapper for DLL side-loading to deploy the Kazuar backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.