logo

RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations

ID: 43db51ea-933a-51e2-a6f1-88102e48a56f

STIX ID: report--43db51ea-933a-51e2-a6f1-88102e48a56f

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-06-24

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Recorded Future's Insikt Group attributes a cyber espionage campaign to a likely China-linked APT cluster called RedJuliett (aka Flax Typhoon / Ethereal Panda) that targeted government, academic, technology, and diplomatic organizations in Taiwan and other countries from Nov 2023 to Apr 2024. The actor focused on internet-facing appliances for initial access (firewalls, load balancers, VPNs), used SQL injection and directory traversal against web/SQL apps, leveraged SoftEther for outbound tunneling, deployed web shells (China Chopper, AntSword, Godzilla) for persistence, and exploited vulnerabilities including Dirty Cow; approximately 24 organizations were observed communicating with the actor's infrastructure and at least 75 Taiwanese entities were targeted for reconnaissance and follow-on exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.