← Back to Actors
RedCurl
RedCurl
[RedCurl](https://attack.mitre.org/groups/G1039) is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks.(Citation: group-ib_redcurl1) [RedCurl](https://attack.mitre.org/groups/G1039) is allegedly a Russian-speaking threat actor.(Citation: group-ib_redcurl1)(Citation: group-ib_redcurl2) The group’s operations typically start with spearphishing emails to gain initial access, then the group execut...
41
Techniques
39
Covered
2
Gaps
95%
Coverage
Coverage39/41
COVERED (39)
T1003.001LSASS Memory105 det.T1005Data from Local System46 det.T1020Automated Exfiltration17 det.T1027Obfuscated Files or Information525 det.T1036.005Match Legitimate Resource Name or Location44 det.T1039Data from Network Shared Drive6 det.T1046Network Service Discovery49 det.T1053.005Scheduled Task82 det.T1056.002GUI Input Capture5 det.T1059.001PowerShell338 det.T1059.003Windows Command Shell79 det.T1059.005Visual Basic66 det.T1059.006Python43 det.T1070.004File Deletion40 det.T1071.001Web Protocols74 det.T1080Taint Shared Content2 det.T1082System Information Discovery80 det.T1083File and Directory Discovery48 det.T1087.001Local Account32 det.T1087.002Domain Account55 det.T1102Web Service33 det.T1114.001Local Email Collection11 det.T1119Automated Collection11 det.T1199Trusted Relationship6 det.T1202Indirect Command Execution56 det.T1204.001Malicious Link9 det.T1204.002Malicious File397 det.T1218.011Rundll3273 det.T1537Transfer Data to Cloud Account26 det.T1547.001Registry Run Keys / Startup Folder50 det.T1552.001Credentials In Files53 det.T1552.002Credentials in Registry7 det.T1555.003Credentials from Web Browsers15 det.T1560.001Archive via Utility24 det.T1564.001Hidden Files and Directories23 det.T1566.001Spearphishing Attachment850 det.T1566.002Spearphishing Link837 det.T1573.002Asymmetric Cryptography6 det.T1587.001Malware9 det.