top of page

RedGolf

Mitre

Alias

Redgolf

Country

China

Sponsor

State-sponsored

Motivation

Information Theft And Espionage

First Seen

2014

Description

(Recorded Future) Recorded Future�s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group.

RedGolf closely overlaps with threat activity reported in open sources under the aliases {{APT 41}}/{{Barium}} and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward. A 2020 US Department of Justice indictment states that a RedGolf-associated threat actor boasted of connections to the Chinese Ministry of State Security (MSS); the indicted actors were also linked to the Chengdu-based company Chengdu 404 Network Technology (??????????????).

Targeted
Industries

Aviation, Automotive, Education, Government, It, Media, Religious Organizations

Targeted
Countries

Usa

Tools

Cobalt Strike
Keyplug
Plugx

TTP

Nil

Operations
Performed

Nil

Counter
Operations

Nil

Information

bottom of page