Security News > 2025 > March > RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment

2025-03-26 13:43
The Russian-speaking hacking group called RedCurl has been linked to a ransomware campaign for the first time, marking a departure in the threat actor's tradecraft. The activity, observed by Romanian cybersecurity company Bitdefender, involves the deployment of a never-before-seen ransomware strain dubbed QWCrypt. RedCurl, also called Earth Kapre and Red Wolf, has a history of orchestrating
News URL
https://thehackernews.com/2025/03/redcurl-shifts-from-espionage-to.html