Cyber Threat Report: 'Unveiling Earth Kapre aka RedCurl’s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence'

Report Author Trend Micro
Publication Date 2024-03-06
Original Reporting Source
Related Intrusion Sets Red Wolf , RedCurl , Earth Kapre

The blog entry details an investigation by Trend Micro's Managed Extended Detection and Response (MDR) team into a cyberespionage incident involving Earth Kapre (aka RedCurl), a threat group known for phishing campaigns across multiple countries. The group employs malicious attachments to infect systems, enabling unauthorized data collection and transmission to command-and-control (C&C) servers. The MDR team's analysis revealed the use of legitimate tools like PowerShell and curl.exe for downloading malware, and the Program Compatibility Assistant (pcalua.exe) to execute malicious commands and evade detection. The investigation also uncovered the abuse of scheduled tasks for persistence and the use of Impacket.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques