Curlc4.txt is a PHP-based email-stealing bot used by Chinese government-linked threat actors associated with Integrity Technology Group. It accesses Microsoft Exchange Web Services to collect email and can access calendar and contact data. Collected messages are compressed and uploaded to remote infrastructure, with some executions additionally encrypting the data using RC4 or AES-128-CBC.
The script supports command-line configuration and searches for writable locations when no working directory is supplied. Its filesystem behavior is consistent with Linux environments. It conceals collection artifacts through obfuscated directory and file names and changes a child process name to disguise its activity.
Curlc4.txt has been used in email-exfiltration operations alongside office-cli. Associated activity overlaps with tracking labels including Flax Typhoon, Ethereal Panda, and Red Juliett, without establishing that these labels represent identical attribution groupings. Observed victims of the associated email-theft operations include government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration.
They use Curlc4.txt, a PHP script, to collect email through the Microsoft EWS API.
“The FBI observed that the threat actors created a bot using the PHP script Curlc4.txt to obtain emails from victims.”
5 distinct techniques documented for this family, organized by ATT&CK tactic.
If the first argument was not supplied, then the script searched for a writeable directory to use as its directory.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named artifact or tool used for email collection during data theft. Its implementation and additional capabilities are not specified.
PHP email-collection and exfiltration script that accesses mailboxes through Exchange Web Services, compresses collected email, and uploads it to a remote server. Some instances encrypt collected data using RC4 or AES-128-CBC. It can locate writable staging directories and uses a hidden ZIP archive path.
A PHP script used by Flax Typhoon to exfiltrate victim email data. The article provides no implementation details.
A PHP-based email collection bot that retrieves mail through Exchange Web Services, compresses it, optionally encrypts it, and uploads it to a remote server. It appears to operate as a stand-alone script rather than an implant on a compromised device. Its main command-and-control domain was natcloudservice[.]com.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.