Trusted Design

RedCurl

アクターID: G1039

· MITRE Pageへのリンク

脅威アクターの詳細

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks.(Citation: group-ib_redcurl1) RedCurl is allegedly a Russian-speaking threat actor.(Citation: group-ib_redcurl1)(Citation: group-ib_redcurl2) The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

脅威アクターの別名・別称

RedCurl

利用した攻撃手法

関連するCVE (攻撃手法に関連)

Actor – Pulse グラフ


← 脅威アクター一覧に戻る