logo

Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain

ID: 279a013f-8405-5ecc-9e1b-50903bc8eb90

STIX ID: report--279a013f-8405-5ecc-9e1b-50903bc8eb90

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-01-09

Date Updated: 2026-04-28

...
...

Insikt Group outlines RedDelta’s July 2023–December 2024 campaign activity in which the Chinese state-aligned APT used adapted infection chains (LNK, MSC, and remotely hosted HTML) to distribute a customized PlugX backdoor against governments, NGOs, activists, and diplomatic targets across Mongolia, Taiwan, Southeast Asia and other countries; the report attributes likely compromises (including the Mongolian Ministry of Defense and the Communist Party of Vietnam), highlights use of Cloudflare to proxy C2, documents evolving TTPs and IoCs, and provides detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.