RedCurl, a cyber-espionage group, expands its operations by deploying ransomware targeting Hyper-V servers.RedCurl historically focused on data exfiltration, but recently started using ransomware in at least one confirmed case.The group uses phishing emails with disguised .img attachments as the initial attack vector.RedCurl's new ransomware, named QWCrypt, specifically encrypts virtual machines hosted on Microsoft Hyper-V.