Sunday, September 13, 2026
Follow on LinkedIn

Redcurl Actors New Ransomware Exclusively Attacking Hyper-V Servers

A new ransomware strain has been discovered targeting virtualized environments, specifically Microsoft Hyper-V servers.

This targeted approach marks a significant evolution in ransomware tactics, as the malware focuses exclusively on hypervisors rather than encrypting all endpoint devices, creating maximum damage with minimum effort.

The malware, named QWCrypt based on a ‘qwc’ self-reference within the executable, is being deployed by the RedCurl threat actor group, also known as Earth Kapre or Red Wolf.

This group has been active since 2018 but has historically maintained a low profile, relying on Living-off-the-Land techniques for corporate espionage and data exfiltration operations.

Bitdefender researchers identified this previously undocumented ransomware and noted that it represents a significant tactical shift for RedCurl.

The analysis reveals a sophisticated operation that demonstrates deep understanding of virtualized environments and careful targeting, setting it apart from conventional ransomware campaigns.

Unlike traditional ransomware that encrypts all endpoints, QWCrypt specifically targets hypervisors, effectively disabling entire virtualized infrastructures while deliberately preserving network gateways.

This strategy appears designed to confine the attack’s impact to IT departments, preventing widespread disruption while still rendering critical systems inaccessible.

Initial access is gained through sophisticated phishing emails containing IMG files disguised as CV documents.

When victims open these attachments, Windows automatically mounts the IMG file as a virtual drive, displaying a file named “CV APPLICANT 7802-91542.SCR” that appears legitimate but harbors malicious intent.

Infection Mechanism Reveals Sophisticated Tactics

The infection mechanism exploits DLL sideloading vulnerabilities in legitimate Adobe executables.

DLL sideloading and order execution hijacking (Source – Bitdefender)

When the victim clicks on the SCR file (which is actually a renamed executable), it loads a malicious netutils.dll that initiates the attack chain while simultaneously distracting the victim by opening a legitimate Indeed login page in their browser.

This malicious DLL acts as a downloader, using wininet.dll functions to retrieve the final payload from a command and control server.

The malware establishes persistence through a scheduled task named “\BrowserSpec\BrowserSpec_” that executes the payload indirectly through a chain of legitimate Windows utilities—a classic example of Living Off The Land techniques.

After gaining initial access and establishing persistence, the attackers deploy the ransomware through custom-crafted batch files specifically tailored to the victim’s environment. The ransomware executes with parameters specifically targeting Hyper-V environments:-

rbcw.exe --hv --excludeVM "wingate,wingate,wingate" --key %tkey% --nosd

This command instructs the malware to encrypt Hyper-V virtual machines while specifically excluding network gateways, demonstrating the attackers’ familiarity with the target infrastructure.

The sophisticated targeting strategy creates a situation where victims maintain network connectivity but cannot access their virtualized infrastructure, facilitating potential discreet ransom negotiations.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks