Organizations in Canada have emerged as the primary target of a targeted cyberattack orchestrated by a threat actor known as STAC6565. Cybersecurity firm Sophos reported that it investigated nearly 40 breaches linked to the threat actor between February 2024 and August 2025. The campaign is believed to share commonalities with a hacking group known as Gold Blade, which is also referred to as Earth Kapre, RedCurl, and Red Wolf.

The financially motivated threat actor is believed to have been active since late 2018. Initially, it targeted entities in Russia before expanding its focus to Canada, Germany, Norway, Slovenia, Ukraine, the United Kingdom, and the United States. The group has a history of using phishing emails to perform commercial espionage.
Recent attacks have shown that RedCurl has been involved in attacks ransomware using a custom malware called QWCrypt. A notable tool in the threat actor's arsenal is RedLoader, which sends information about the infected computer to a command and control (C2) server and runs PowerShell scripts to collect details related to the compromised Active Directory (AD) environment.
See also: FinCEN: Ransomware gangs stole over $2.1 billion from 2022 to 2024
“This campaign reflects an unusually narrow geographic focus for the group, with nearly 80% of attacks targeting Canadian organizations,” said Sophos researcher Morgan Demboski. “Initially focused on cyberespionage, Gold Blade has evolved its activity into a hybrid operation that combines data theft with selective ransomware deployment via a custom locker called QWCrypt.”
Other major targets include the U.S., Australia, and the U.K., with the services, manufacturing, retail, technology, non-governmental organizations, and transportation sectors being hit hardest during this period.
The group is said to operate under a “hack-for-hire” model, performing custom breaches on behalf of clients, while developing ransomware to financially exploit the breaches. Although a 2020 report by Group-IB indicated that it is likely a Russian-speaking group, there is currently no evidence to confirm or deny this assessment.
Describing RedCurl as a “professional operation,” Sophos noted that the threat actor stands out from other cybercriminal groups due to its ability to refine and evolve its technique, as well as to carry out subtle extortion attacks. There is no evidence to suggest it is state-backed or politically motivated.
The operational rhythm is characterized by periods of inactivity followed by sudden attacks with improved tactics, indicating that the hacking group may be using the idle time to refresh its toolkit.
See also: Industry is doing better against ransomware

STAC6565: How do attacks work in Canada?
STAC6565 begins with spear-phishing emails targeting human resources (HR) staff at companies. The goal is to trick employees into opening malicious documents posing as resumes or cover letters. Since at least November 2024, the activity has leveraged legitimate job search platforms such as Indeed, JazzHR, and ADP WorkforceNow to upload malicious resumes as part of a job application process.
“As recruiting platforms allow HR staff to review all incoming resumes, hosting payloads on these platforms and delivering them via temporary email domains not only increases the likelihood that the documents will be opened but also avoids detection by email-based protections,” Demboski explained.
In one incident, a fake resume uploaded to Indeed redirected users to a URL that ultimately led to the deployment of QWCrypt ransomware via a RedLoader. At least three different RedLoader delivery sequences have been observed in September 2024, March/April 2025, and July 2025. Some aspects of the delivery chains have been previously analyzed by Huntress, eSentire, and Bitdefender.
The main change observed in July 2025 concerns the use of a ZIP file that is installed by the fake resume. Inside the file is a Windows shortcut (LNK) that mimics a PDF. The LNK file uses “rundll32.exe” to retrieve a renamed version of “ADNotificationManager.exe” from a WebDAV server, hosted behind a Cloudflare Workers domain.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Cybersecurity Resilience: Cheapest is not always best
The attack then launches the legitimate Adobe executable to load the RedLoader DLL (named “srvcli.dll” or “netutils.dll”) from the same WebDAV path. The DLL then proceeds to connect to an external server, download and execute the second-stage payload. This is a standalone binary that is responsible for connecting to a different server and retrieving the standalone third-stage executable (along with a malicious DAT file and a renamed 7-Zip archive).
Both stages rely on Program Compatibility Assistant ("pcalua.exe") to execute the payload, an approach seen in previous campaigns. The only difference is that the format of the payloads changed in April 2025 to EXE instead of DLL.

“The payload parses the malicious .dat file and checks the internet connection. It then connects to another C2 server controlled by the attacker to create and execute a .bat script that automates system discovery,” Sophos said. “The script unzips Sysinternals AD Explorer and runs commands to collect details such as host information, disks, processes, and installed antivirus (AV) products.”
The results of the execution are packaged into an encrypted, password-protected 7-Zip archive. They are then transferred to a WebDAV server controlled by the attacker. RedCurl has also been observed using RPivot, an open-source reverse proxy, and Chisel SOCKS5 for C2 communications.
Another tool used in the attacks is a customized version of the Terminator tool, which leverages a signed Zemana AntiMalware driver to terminate antivirus-related (via what is called a Bring Your Own Vulnerable Driver – BYOVD attack). In at least one case, the threat actors renamed both components before distributing them via SMB shares to all servers in the victim’s environment.
See also: JS#SMUGGLER: Compromised websites for NetSupport RAT deployment
Sophos also noted that the majority of these attacks were detected and mitigated before QWCrypt was deployed. However, three of the attacks – one in April and two in July 2025 – resulted in successful deployment.
“In the April incident, threat actors manually browsed and collected sensitive files. They then paused the activity for over five days before deploying the locker,” he added. “This delay may indicate that the attackers turned to ransomware after trying to monetize the data or failing to secure a buyer.”

QWCrypt deployment scripts are tailored to the target environment and often contain a victim-specific identifier in the file names. Once the script is launched, it checks to see if the Terminator service is running, before taking steps to disable recovery and execute the ransomware on endpoint devices across the network (including an organization's hypervisors).
In the final stage, the script runs a cleanup batch script to delete existing shadow copies and any PowerShell console history files (to prevent forensic recovery).
