Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain
ID: 279a013f-8405-5ecc-9e1b-50903bc8eb90
STIX ID: report--279a013f-8405-5ecc-9e1b-50903bc8eb90
Feed Name: Recorded Future Blog
Insikt Group outlines RedDelta’s July 2023–December 2024 campaign activity in which the Chinese state-aligned APT used adapted infection chains (LNK, MSC, and remotely hosted HTML) to distribute a customized PlugX backdoor against governments, NGOs, activists, and diplomatic targets across Mongolia, Taiwan, Southeast Asia and other countries; the report attributes likely compromises (including the Mongolian Ministry of Defense and the Communist Party of Vietnam), highlights use of Cloudflare to proxy C2, documents evolving TTPs and IoCs, and provides detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
