HomeSecurityRedCurl hackers: They turn from espionage to ransomware

RedCurl hackers: They turn from espionage to ransomware

The hackers "RedCurl", who have been engaged in espionage operations since 2018, have now turned to ransomware attacks (QWCrypt) which target Hyper-V virtual machines.

RedCurl hackers QWCrypt ransomware

Previous observations by Group-IB showed that the RedCurl group had targeted corporate entities around the world. However, Bitdefender Labs now say that threat actors have also begun deploying ransomware on compromised networks. In addition, hackers are stealing victims' data.

This is the first time researchers have seen hackers deploy ransomware.
While most ransomware operations focus on targeting VMware ESXi servers, the new ransomware “QWCrypt” used by RedCurl hackers targets Hyper-V virtual machines.

QWCrypt – Ransomware Attacks

According to Bitdefender, the attacks start with phishing emails containing “.IMG” attachments disguised as resumes. IMG files are disk image files and contain a screensaver file vulnerable to DLL sideloading (using a legitimate Adobe executable, which downloads a payload and sets persistence via a scheduled task).

See also: Arkana ransomware group says it breached WideOpenWest

RedCurl hackers use “living-off-the-land” tools to remain hidden inside Windows systems. They also use a custom wmiexec variant to spread laterally across the network without triggering security tools. Finally, the “Chisel” tool is used for tunneling/RDP access.

To disable defenses before deploying the QWCrypt ransomware, RedCurl hackers use encrypted 7z files and a multi-stage PowerShell process.

QWCrypt supports several command-line arguments that control how the cryptographer will target Hyper-V virtual machines to tailor attacks.

According to Bitdefender, the RedCurl team used the excludeVM argument to avoid encrypting virtual machines that acted as network gateways, to avoid disruption.

When encrypting files, QWCrypt ('rbcw.exe') uses the XChaCha20-Poly1305 encryption algorithm and appends either the .locked$ or .randombits$ extension to encrypted files. There is also the option for intermittent encryption or selective file encryption.

The ransom note created by QWCrypt is called “!!!how_to_unlock_randombits_files.txt$”.

See also: What you need to know about Ransomware-as-a-Service (RaaS)

At present, no dedicated data leak site has been identified, which raises questions about whether the RedCurl hackers are using the ransomware as a false flag or for actual extortion attacks.

Bitdefender outlines two main hypotheses for why the RedCurl group is now including ransomware in its attacks.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The first hypothesis is that RedCurl offers services to third parties, which results in a combination of espionage operations and financially motivated.

The second hypothesis is that RedCurl hackers do engage in ransomware operations to enrich their attacks, but they choose to do so covertly, preferring private negotiations over public ransom demands and data leaks.

RedCurl hackers: They turn from espionage to ransomware

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a  attack  is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest  security  and software updates to prevent any vulnerabilities that could be exploited by ransomware.

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

See also: Medusa Ransomware disables security tools with a malicious driver

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent attacks  . Be sure to update your antivirus software to ensure it is equipped to handle new threats.

Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS