QWCrypt is a ransomware threat group identified as an emerging actor in 2025 and reported to have links to RedCurl. It has been tracked among rising ransomware operations during a period of fragmentation and affiliate movement across the broader ransomware ecosystem. High-confidence reporting in the available material supports its classification as a ransomware actor and notes an association with RedCurl, but provides limited detail on its victimology, tooling, or operational tradecraft beyond that linkage. Based on the available facts, QWCrypt should be understood as a developing ransomware cluster rather than a fully profiled intrusion set. No specific country of origin, target geography, sector focus, extortion model, or detailed capability set is directly established by the supplied information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.