Cyber Hacking News

RedCurl Cyberspies deploy Ransomware to target Hyper-V Servers

0

RedCurl, a cyber-espionage group active since 2018, has expanded its operations by deploying ransomware designed to encrypt Hyper-V virtual machines, marking a shift from its usual corporate espionage tactics.

According to Bitdefender Labs, RedCurl has historically focused on prolonged data exfiltration but recently deployed ransomware in at least one confirmed case. This move aligns with a growing trend among cybercriminals targeting virtualization platforms as enterprises increasingly rely on virtual machines.

Unlike many ransomware groups that target VMware ESXi servers, RedCurl’s newly developed ransomware, dubbed “QWCrypt,” specifically encrypts virtual machines hosted on Microsoft Hyper-V.

Attack Methodology

Bitdefender researchers observed that RedCurl initiates attacks using phishing emails with .img attachments masquerading as resumes. Once opened, these disk image files mount as virtual drives in Windows, deploying a screensaver file that exploits DLL sideloading via a legitimate Adobe executable. This process downloads and executes a payload while maintaining persistence through scheduled tasks.

RedCurl employs various stealth techniques, including:

  • Living-off-the-land (LotL) tools to avoid detection.

  • A custom wmiexec variant for lateral movement.

  • The Chisel tool for tunneling and remote desktop access.

  • Encrypted 7z archives and multi-stage PowerShell scripts to disable security defenses before executing ransomware.

QWCrypt provides attackers with multiple command-line options to tailor encryption processes. One notable feature is the –excludeVM argument, allowing attackers to bypass certain virtual machines, such as network gateways, to avoid drawing attention.

The ransomware uses the XChaCha20-Poly1305 encryption algorithm and appends .locked$ or .randombits$ extensions to encrypted files. It also supports intermittent encryption and selective file encryption for faster execution.

Bitdefender proposes two potential motives for RedCurl’s pivot to ransomware. RedCurl may act as a mercenary group conducting both espionage and financially motivated attacks. The ransomware could serve as a distraction to conceal data theft or provide alternative monetization if clients fail to pay for espionage services. Unlike traditional ransomware groups, RedCurl might prefer private negotiations over public ransom demands and data leaks, maintaining a low profile while still profiting.

RedCurl’s adoption of ransomware marks a significant shift in its strategy. Organizations are urged to strengthen defenses against phishing attacks and implement security measures to protect virtual environments from emerging threats.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

CISA warns of actively exploited Fortinet FortiOS Vulnerability

Previous article

OpenAI raises maximum Bug Bounty to $100,000 for Critical Vulnerabilities

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *