Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1039
MITRE ATT&CK Group

RedCurl (G1039)

ShareXLinkedInRedditHN

[RedCurl](https://attack.mitre.org/groups/G1039) is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks.(Citation: group-ib_redcurl1) [RedCurl](https://attack.mitre.org/groups/G1039) is allegedly a Russian-speaking threat actor.(Citation: group-ib_redcurl1)(Citation: group-ib_redcurl2) The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.

▪Techniques used (41)

T1027Obfuscated Files or InformationT1564.001Hidden Files and DirectoriesT1102Web ServiceT1114.001Local Email CollectionT1039Data from Network Shared DriveT1080Taint Shared ContentT1204.002Malicious FileT1005Data from Local SystemT1119Automated CollectionT1083File and Directory DiscoveryT1059.003Windows Command ShellT1059.001PowerShellT1036.005Match Legitimate Resource Name or LocationT1566.001Spearphishing AttachmentT1059.005Visual BasicT1560.001Archive via UtilityT1573.001Symmetric CryptographyT1071.001Web ProtocolsT1087.003Email AccountT1587.001MalwareT1087.001Local AccountT1056.002GUI Input CaptureT1082System Information DiscoveryT1204.001Malicious LinkT1573.002Asymmetric CryptographyT1053.005Scheduled TaskT1020Automated ExfiltrationT1199Trusted RelationshipT1537Transfer Data to Cloud AccountT1202Indirect Command ExecutionT1552.001Credentials In FilesT1218.011Rundll32T1087.002Domain AccountT1566.002Spearphishing LinkT1552.002Credentials in RegistryT1070.004File DeletionT1547.001Registry Run Keys / Startup FolderT1555.003Credentials from Web BrowsersT1059.006PythonT1003.001LSASS MemoryT1046Network Service Discovery
G1039on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.