
The International Computer Security Company Group-IB reported the previously unknown Russian-speaking hacker group Redcurl, which stole important corporate information among private companies around the world, according to the Group-IB website.
According to Group-Ib, Redcurl has existed since 2018. During this time, hackers made 26 targeted attacks exclusively on commercial organizations. Among them are construction, financial, consulting companies, retailers, banks, insurance, legal and tourist organizations.
“Redcurl does not have a clear geographical binding to any region: its victims were located in Russia, Ukraine, Great Britain, Germany, Canada and Norway,” said Group-Ib Threat Intelligence experts who discovered hackers.
They noted that hackers act as secretly as possible to minimize the risk of detection. The main goal of cybercriminals is the theft of confidential corporate documents: contracts, financial documentation, personal cases of employees, documents on court cases, construction of facilities and others. “All this may indicate the custom nature of Redcurl attacks for the purpose of unfair competition,” Group-Ib representatives say.
To hack the network of the company, hackers use phishing letters that are carefully compiled for a specific team inside the victim. They attack several employees of the same department, sending, for example, information about annual bonuses. Once on the network, hackers scan the data and send it to a cloud, where the Redcurl operator decides which folders and files to save.
“Corporate espionage in order to compete is a rare phenomenon on the hacker stage, but the frequency of attacks suggests that, most likely, it will be further distributed. At the moment, Group-Ib continues to record new Redcurl attacks in different countries of the world, ”experts said.