Group-IB reported renewed activity by RedCurl, a Russian-speaking cyber-espionage group focused on stealing internal corporate documents from organizations across multiple industries. The company said the actor carried out four additional intrusions after a seven-month lull, raising the total number of observed attacks to 30, with activity tracked from 2018 through 2021. RedCurl’s operations were described as long-running and covert, typically lasting two to six months inside victim environments.
Investigators said the group relied on spear-phishing emails disguised as HR communications and used an expanded five-stage infection chain that now includes the FSABIN reconnaissance tool and a PowerShell downloader. Group-IB said RedCurl continues to favor self-developed malware over common post-exploitation frameworks, with campaigns aimed at exfiltrating sensitive business, legal, and personnel records rather than deploying ransomware or stealing money.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
BI.ZONE Cyber Threat Intelligence published analysis of a RedCurl (Red Wolf) campaign using an optical disk image with an LNK file and hidden DLLs to launch rundll32 and download the RedCurl.FSABIN backdoor from amscloudhost infrastructure. The report also detailed persistence via a scheduled task, anti-virtualization checks, host reconnaissance, follow-on DLL execution, and campaign IOCs including domains and SHA-256 hashes.
Since the beginning of 2021, RedCurl conducted four more attacks, bringing Group-IB's total observed count to 30. One victim was a Russian wholesale company that was attacked twice, while two other 2021 victims' locations were unknown.
After a seven-month lull, RedCurl resumed operations in 2021. Group-IB said the renewed activity marked a new phase in the threat actor's corporate espionage campaign.
Between 2018 and 2020, RedCurl carried out at least 26 corporate espionage attacks against organizations in sectors including construction, finance, consulting, retail, insurance, and law. Group-IB identified 14 victim organizations across countries including the UK, Germany, Canada, Norway, Russia, and Ukraine.
Group-IB published a report detailing renewed RedCurl activity, its updated tooling, and its continued focus on stealing internal corporate documentation rather than deploying ransomware or stealing funds. The report characterized RedCurl as a rare example of commercial corporate cyber espionage.
Analysis of RedCurl's latest attacks showed its kill chain had grown from three stages to five. The updated toolset included the FSABIN reconnaissance tool and a PowerShell downloader, reflecting an evolution in the group's tactics and malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.