Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Deadmau5 adopts a cat he rescued by donating to an animal shelter

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » RedCurl moves from spy to ransomware with the first ever QWCRYPT deployment
Celebrities

RedCurl moves from spy to ransomware with the first ever QWCRYPT deployment

By March 26, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 26, 2025Hacker NewsRansomware/Endpoint Security

A Russian-speaking hacking group called RedCurl has been linked for the first time to a ransomware campaign that marks the departure of a merchant of threat actors.

Activities observed by Romanian cybersecurity company BitDefender include the unprecedented development of ransomware stocks, called QWCrypt.

Redcurl, also known as Earth Capre and Redwolf, has a history of coordinating corporate spy attacks targeting a variety of entities in Canada, Germany, Norway, Russia, Slovenia, Ukraine, the UK and the US. It has been known to be active since at least November 2018.

Cybersecurity

The attack chain documented by Group-IB in 2020 required the use of spear phishing emails, including human resources (HR)-themed lures, to activate the malware deployment process. Earlier this January, Huntress deployed a loader called the Red Loader, sprayed with a “simple backdoor feature” that was fitted with detailed attacks installed by threat actors targeting several Canadian organizations.

Then last month, Canadian cybersecurity company Esentire revealed the use of a spam PDF attachment equipped with CVS and cover letters for sideloading loader malware using the legitimate Adobe executable “AdnotificationManager.exe”.

The attack sequence detailed by BitDefender traces the same steps as using a Multitable Disk Image (ISO) file to impersonate a CVS to initiate a multistage infection procedure. What resides in the disk image is a file that mimics Windows Screensaver (SCR), but in reality it is the AdnotificationManager.exe binary used to run the loader (“Netutils.dll”) using DLL sideload.

“After execution, netutils.dll immediately launches a shellexecutea call with an open verb and directs the victim’s browser to https://secure.indeed.com/auth,” said Martin Zugec, director of technical solutions at Bitdefender, in a report shared with Hacker News.

“This will give you a legitimate login page. It is a calculated distraction designed to mislead the victim, designed to simply think of your resume as open. This social engineering tactic provides a window for malware to work undetected.”

Image source: etenire

The per-BitDefender loader also serves as a downloader for the next stage of the backdoor DLL, establishing host persistence through scheduled tasks. The newly searched DLLs will then be run using Program Compatibility Assistant (PCALUA.EXE), a technology detailed by Trend Micro in March 2024.

The access provided by implants paves the way for lateral movement, allowing threat actors to navigate the network, gather intelligence, and escalate access. But in what appears to be a major pivot from established modalities, one such attack was first deployed in ransomware deployment.

Cybersecurity

“This focused targeting can be interpreted as an attempt to inflict maximum damage with minimal effort,” Zugek said. “By encrypting virtual machines hosted on the hypervisor, and preventing them from being started, RedCurl effectively disables the entire virtualized infrastructure and affects all hosted services.”

In addition to employing its own Vulnerable Driver (BYOVD) technique to disable Endpoint Security software, Ransomware executable takes steps to collect system information before invoking the encryption routine. Furthermore, the ransom notes dropped after encryption seem to be inspired by Lockbit, Hardbit and imitation groups.

“This practice of reusing the text of existing ransom memos raises questions about the origins and motivations of the RedCurl group,” Zugec said. “In particular, there are no known dedicated leak sites (DLS) related to this ransomware. It remains unknown whether the ransom notes represent a genuine terror attempt or a conversion.”

Did you find this article interesting? This article is a donation from one of our precious partners. Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBlacklist more than 50 Chinese tech companies to curb the advances of AI and quantum in China
Next Article Encrypthub exploits Windows Zero-day to deploy Rhadamanthys and StealC malware

Related Posts

Katie Holmes evokes ‘office siren’ at Max Mara Resort 2027 show

June 16, 2026

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Deadmau5 adopts a cat he rescued by donating to an animal shelter

Ranking of all official World Cup songs

Trending Posts

Deadmau5 adopts a cat he rescued by donating to an animal shelter

June 16, 2026

Ranking of all official World Cup songs

June 16, 2026

Jennifer Lopez needed to find herself again after divorce from Affleck

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.