RedCurl is a long-running intrusion set known primarily for targeted corporate espionage against organizations in multiple regions, including Europe, North America, and Australia. It is also tracked as Earth Kapre, Red Wolf, and GOLD BLADE. Reporting has consistently characterized the group as focused on intelligence collection from business environments rather than disruptive or overtly destructive operations, although it uses tradecraft commonly associated with mature criminal and espionage actors. RedCurl is notable for highly tailored phishing and social-engineering campaigns, including job- or business-themed lures that deliver malicious archives, shortcut files, and staged loaders. The group has used custom malware such as RedLoader and has relied on DLL sideloading, renamed legitimate executables, and multi-stage infection chains to establish execution while blending into normal Windows activity. It has also used malicious files, batch scripts, PowerShell, and the Windows command interpreter during execution and staging. Observed delivery and command channels include HTTP, HTTPS, WebDAV, and abuse of cloud services. Post-compromise, RedCurl has demonstrated a strong emphasis on internal reconnaissance and data collection. Documented behaviors include gathering system information, enumerating network connections, collecting data from local disks, and performing domain account discovery, including use of AdExplorer functionality to inspect Active Directory environments. The group has also used LaZagne to obtain credentials from files and local application stores, aligning with credential access objectives often seen in espionage operations. For persistence and defense evasion, RedCurl has used Registry Run autoruns, scheduled tasks masquerading as legitimate maintenance or update activity, hidden-file attributes, string and data encryption, Base64-encoded PowerShell, and obfuscation techniques including PyArmor in support tooling. It has also deleted files after execution to reduce forensic visibility. The group commonly mimics legitimate filenames and task names to hinder detection and analyst triage. Overall, RedCurl is best understood as a stealth-focused espionage actor that combines spearphishing, living-off-the-land execution, custom loaders, credential theft, directory reconnaissance, and selective anti-forensic measures to penetrate and surveil enterprise targets. Known aliases include Earth Kapre, Red Wolf, and GOLD BLADE.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in annotations associated with the credential-access technique.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Referenced as a threat actor that used DLL sideloading.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.