Meta tags:
Headings (most frequently used words):
redcurl, techniques, used, references, enterprise, layer,
Text of the page (most frequently used words):
redcurl (53), has (39), #enterprise (38), used (28), and (25), the (20), files (18), data (15), 001 (13), att (11), malicious (11), all (10), collected (9), execution (8), for (8), about (7), file (7), credentials (7), account (7), information (7), discovery (7), from (7), command (7), 2024 (6), with (6), group (6), 002 (6), network (6), local (6), ics (5), mobile (5), none (5), august (5), web (5), lazagne (5), system (5), execute (5), scheduled (5), phishing (5), commands (5), mitre (4), use (4), techniques (4), retrieved (4), obtain (4), passwords (4), access (4), emails (4), email (4), collection (4), scripting (4), interpreter (4), version (4), 2026 (3), campaigns (3), software (3), groups (3), cti (3), defenses (3), tactics (3), threat (3), download (3), service (3), victim (3), user (3), registry (3), exfiltrate (3), drives (3), created (3), tasks (3), 005 (3), gain (3), initial (3), spearphishing (3), malware (3), encrypted (3), powershell (3), using (3), tools (3), operations (3), 003 (3), run (3), windows (3), scripts (3), accounts (3), domain (3), corporation (2), are (2), domains (2), resources (2), reference (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), matrices (2), core (2), objects (2), july (2), russian (2), bank (2), infect (2), machines (2), links (2), link (2), unsecured (2), cloud (2), storage (2), modified (2), lnk (2), shared (2), connections (2), rundll32 (2), exe (2), binary (2), persistence (2), task (2), memory (2), obfuscate (2), obfuscated (2), downloaded (2), names (2), port (2), open (2), legitimate (2), name (2), location (2), microsoft (2), input (2), capture (2), hidden (2), https (2), communication (2), cryptography (2), channel (2), communications (2), browsers (2), password (2), python (2), batch (2), automated (2), archive (2), layer (2), g1039 (2), actor (2), corporate (2), variety (2), including (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, antoniuk, 2023, hackers, return, spy, major, australian, company, tancio, march, unveiling, earth, kapre, aka, cyberespionage, trend, micro, mdr, intelligence, 2021, november, awakening, 2020, pentest, you, didn, know, references, services, t1102, t1204, t1552, gained, contractor, pivot, infrastructure, trusted, relationship, t1199, particular, megatools, utilities, were, mega, transfer, t1537, placed, lateral, movement, taint, content, t1080, target, such, list, t1082, proxy, 011, t1218, job, t1053, attachment, t1566, lsass, credential, dumping, t1003, string, encryption, also, encoded, base64, code, additionally, renaming, them, commonly, instead, themselves, echo, pyarmor, t1027, netstat, check, 4119, t1046, mimicked, mask, mdmmaintenencetask, microsoftcurrentupdatescheck, match, resource, masquerading, t1036, prompts, through, outlook, pop, gui, t1056, pcalua, remote, indirect, t1202, deleted, after, deletion, indicator, removal, 004, t1070, added, attribute, original, manipulating, victims, click, directories, hide, artifacts, t1564, searched, directory, t1083, asymmetric, aes, 128, cbc, encrypt, symmetric, t1573, future, t1114, its, own, during, develop, capabilities, t1587, drive, t1039, disk, compromised, hosts, t1005, stores, t1555, script, establish, outbound, smb, 445, 006, vbscript, visual, basic, prompt, shell, t1059, established, creating, entries, hkcu, currentversion, keys, startup, folder, boot, logon, autostart, t1547, exfiltration, t1020, collect, t1119, zip, decompress, protected, archives, via, utility, t1560, http, webdav, protocls, protocols, application, protocol, t1071, sysinternal, adexplorer, functionality, t1087, view, navigator, layers, live, permalink, last, september, joe, gumke, contributors, active, since, 2018, notable, espionage, targeting, locations, ukraine, canada, united, kingdom, industries, but, not, limited, travel, agencies, insurance, companies, banks, allegedly, speaking, typically, start, then, executes, find, concludes, exfiltrating, servers, home, join, october, mclean, hotel, details, can, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, get, started, detections,
Text of the page (random words):
redcurl group g1039 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home groups redcurl redcurl redcurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations including ukraine canada and the united kingdom and a variety of industries including but not limited to travel agencies insurance companies and banks 1 redcurl is allegedly a russian speaking threat actor 1 2 the group s operations typically start with spearphishing emails to gain initial access then the group executes discovery and collection commands and scripts to find corporate data the group concludes operations by exfiltrating files to the c2 servers id g1039 contributors joe gumke u s bank version 1 0 created 23 september 2024 last modified 31 july 2026 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1087 001 account discovery local account redcurl has collected information about local accounts 1 2 002 account discovery domain account redcurl has collected information about domain accounts using sysinternal s adexplorer functionality 1 2 003 account discovery email account redcurl has collected information about email accounts 1 2 enterprise t1071 001 application layer protocol web protocols redcurl has used http https and webdav protocls for c2 communications 1 2 enterprise t1560 001 archive collected data archive via utility redcurl has downloaded 7 zip to decompress password protected archives 3 enterprise t1119 automated collection redcurl has used batch scripts to collect data 1 2 enterprise t1020 automated exfiltration redcurl has used batch scripts to exfiltrate data 1 2 enterprise t1547 001 boot or logon autostart execution registry run keys startup folder redcurl has established persistence by creating entries in hkcu software microsoft windows currentversion run 1 2 enterprise t1059 001 command and scripting interpreter powershell redcurl has used powershell to execute commands and to download malware 1 2 3 003 command and scripting interpreter windows command shell redcurl has used the windows command prompt to execute commands 1 2 3 005 command and scripting interpreter visual basic redcurl has used vbscript to run malicious files 1 2 006 command and scripting interpreter python redcurl has used a python script to establish outbound communication and to execute commands using smb port 445 3 enterprise t1555 003 credentials from password stores credentials from web browsers redcurl used lazagne to obtain passwords from web browsers 1 2 enterprise t1005 data from local system redcurl has collected data from the local disk of compromised hosts 1 2 enterprise t1039 data from network shared drive redcurl has collected data about network drives 1 2 enterprise t1587 001 develop capabilities malware redcurl has created its own tools to use during operations 4 enterprise t1114 001 email collection local email collection redcurl has collected emails to use in future phishing campaigns 1 enterprise t1573 001 encrypted channel symmetric cryptography redcurl has used aes 128 cbc to encrypt c2 communications 2 002 encrypted channel asymmetric cryptography redcurl has used https for c2 communication 1 2 enterprise t1083 file and directory discovery redcurl has searched for and collected files on local and network drives 4 1 2 enterprise t1564 001 hide artifacts hidden files and directories redcurl added the hidden file attribute to original files manipulating victims to click on malicious lnk files 1 2 enterprise t1070 004 indicator removal file deletion redcurl has deleted files after execution 1 2 3 enterprise t1202 indirect command execution redcurl has used pcalua exe to obfuscate binary execution and remote connections 3 enterprise t1056 002 input capture gui input capture redcurl prompts the user for credentials through a microsoft outlook pop up 1 2 enterprise t1036 005 masquerading match legitimate resource name or location redcurl mimicked legitimate file names and scheduled tasks e g microsoftcurrentupdatescheck and mdmmaintenencetask to mask malicious files and scheduled tasks 1 2 enterprise t1046 network service discovery redcurl has used netstat to check if port 4119 is open 3 enterprise t1027 obfuscated files or information redcurl has used malware with string encryption 4 redcurl has also encrypted data and has encoded powershell commands using base64 1 2 redcurl has used pyarmor to obfuscate code execution of lazagne 1 additionally redcurl has obfuscated downloaded files by renaming them as commonly used tools and has used echo instead of file names themselves to execute files 3 enterprise t1003 001 os credential dumping lsass memory redcurl used lazagne to obtain passwords from memory 1 2 enterprise t1566 001 phishing spearphishing attachment redcurl has used phishing emails with malicious files to gain initial access 1 3 002 phishing spearphishing link redcurl has used phishing emails with malicious links to gain initial access 1 2 enterprise t1053 005 scheduled task job scheduled task redcurl has created scheduled tasks for persistence 1 2 3 enterprise t1218 011 system binary proxy execution rundll32 redcurl has used rundll32 exe to execute malicious files 1 2 3 enterprise t1082 system information discovery redcurl has collected information about the target system such as system information and list of network connections 1 2 enterprise t1080 taint shared content redcurl has placed modified lnk files on network drives for lateral movement 1 2 enterprise t1537 transfer data to cloud account redcurl has used cloud storage to exfiltrate data in particular the megatools utilities were used to exfiltrate data to mega a file storage service 1 2 enterprise t1199 trusted relationship redcurl has gained access to a contractor to pivot to the victim s infrastructure 4 enterprise t1552 001 unsecured credentials credentials in files redcurl used lazagne to obtain passwords in files 1 2 002 unsecured credentials credentials in registry redcurl used lazagne to obtain passwords in the registry 1 2 enterprise t1204 001 user execution malicious link redcurl has used malicious links to infect the victim machines 1 2 002 user execution malicious file redcurl has used malicious files to infect the victim machines 1 2 3 enterprise t1102 web service redcurl has used web services to download malicious files 1 2 references group ib 2020 august redcurl the pentest you didn t know about retrieved august 9 2024 group ib 2021 november redcurl the awakening retrieved august 14 2024 tancio et al 2024 march 6 unveiling earth kapre aka redcurl s cyberespionage tactics with trend micro mdr threat intelligence retrieved august 9 2024 antoniuk d 2023 july 17 redcurl hackers return to spy on major russian bank australian company retrieved august 9 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|