Sharpening the knife: GOLD BLADE’s strategic evolution
news.sophos.com·1d
🎫Kerberos Attacks
Preview
Report Post

Between February 2024 and August 2025, Sophos analysts investigated nearly 40 intrusions related to STAC6565, a campaign the analysts assess with high confidence is associated with the GOLD BLADE threat group (also known as RedCurl, RedWolf, and Earth Kapre). This campaign reflects an unusually narrow geographic focus for the group, with almost 80% of the attacks targeting Canadian organizations. Once focused primarily on cyberespionage, GOLD BLADE has evolved its activity into a hybrid operation that blends data theft with selective ransomware deployment via a custom locker named QWCrypt.

GOLD BLADE continually refines its intrusion methods and has shifted from trad…

Similar Posts

Loading similar posts...