← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
RedAlpha Conducts Multi-Year Credential Theft Campaign Targeting Global Humanitarian, Think Tank, and Government Organizations
Over the past 3 years, Recorded Future have observed RedAlpha registering
and weaponizing hundreds of domains spoofing organizations
such as the International Federation for Human Rights (FIDH),
Amnesty International, the Mercator Institute for China Studies
(MERICS), Radio Free Asia (RFA), the American Institute in Taiwan
(AIT), and other global government, think tank, and humanitarian
organizations that fall within the strategic interests of the Chinese
government. Historically, the group has also engaged in direct
targeting of ethnic and religious minorities, including individuals
and organizations within Tibetan and Uyghur communities. As
highlighted within this report, in recent years RedAlpha has also
displayed a particular interest in spoofing political, government,
and think tank organizations in Taiwan, likely in an effort to
gather political intelligence.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 451 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 6197a69f4391998acd05a250e25b7e85 | MD5 of f3384e36784f88f2c83ff524f99accbc7bb3b2804a936c0d9cf10da749eca10d | 2022-08-17 |