top of page
Mitre
Alias
Redgolf
Country
China
Sponsor
State-sponsored
Motivation
Information Theft And Espionage
First Seen
2014
Description
(Recorded Future) Recorded Future�s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group.
RedGolf closely overlaps with threat activity reported in open sources under the aliases {{APT 41}}/{{Barium}} and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward. A 2020 US Department of Justice indictment states that a RedGolf-associated threat actor boasted of connections to the Chinese Ministry of State Security (MSS); the indicted actors were also linked to the Chengdu-based company Chengdu 404 Network Technology (??????????????).
Targeted
Industries
Aviation, Automotive, Education, Government, It, Media, Religious Organizations
Targeted
Countries
Usa
Tools
Cobalt Strike
Keyplug
Plugx
TTP
Nil
Operations
Performed
Nil
Counter
Operations
Nil
Information
bottom of page