PULSE NAME
RedDelta: Chinese State-Sponsored Group Targets Mongolia, Taiwan, and Southeast Asia with Evolving Cyber Threats
WHITE RedDelta AlienVault 2025-01-09 Modified: 2025-02-08
281
IOCs
HIGH VOLUME
Between July 2023 and December 2024, the Chinese state-sponsored group RedDelta targeted Mongolia, Taiwan, and Southeast Asian countries with an adapted infection chain to distribute its customized PlugX backdoor. The group used themed lure documents and evolved its tactics, transitioning from Windows Shortcut files to Microsoft Management Console Snap-In Control files, and finally to HTML files hosted on Microsoft Azure. RedDelta consistently used Cloudflare CDN to proxy command-and-control traffic, blending with legitimate traffic. The group's activities align with Chinese strategic priorities, focusing on governments and diplomatic organizations in the targeted regions.
Indicators of Compromise (31 / 281 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 011478f93a06a229d2a2a65320571f5f 2025-01-09
FileHash-MD5 012ffc7ae4d2ba4e725c0a47f69b3372 2025-01-09
FileHash-MD5 084fe5e54dbf4d7287b48c5695d02d17 2025-01-09
FileHash-MD5 12d532ad425a2e62083f5a448f46a141 2025-01-09
FileHash-MD5 204a12016c46d31d615c38b13f6ad7ec 2025-01-09
FileHash-MD5 226b14ecc07e900a2ee4fd99db2d4489 2025-01-09
FileHash-MD5 32c26797ab646074a2bb562f9d10adb5 2025-01-09
FileHash-MD5 3d185e12ce7e5e8664ffa56743db8b39 2025-01-09
FileHash-MD5 5968126b6f6c64e8ee24c60a15c0c684 2025-01-09
FileHash-MD5 5eae3d3b9aeeb0a4186ad3b68ff2da59 2025-01-09
FileHash-MD5 5f39a964af306f40536aa6ac57b66758 2025-01-09
FileHash-MD5 6aeeedbc67d02e4b2a5a5440570d4319 2025-01-09
FileHash-MD5 6da30fa0f72aeb1f4d399ddfffeea04d 2025-01-09
FileHash-MD5 7ce04c9b2232823200b7e9d96466288e 2025-01-09
FileHash-MD5 8b1fd0d5bbd453a52406fcae1b18c192 2025-01-09
FileHash-MD5 9794bd903f9baf249251c3beb693fbc9 2025-01-09
FileHash-MD5 97bed8414045728b9628cb64b7a9a088 2025-01-09
FileHash-MD5 9ee6e8f633764c06142c9abeddb9f04c 2025-01-09
FileHash-MD5 ad94326af3736562be6d699ae3122e5e 2025-01-09
FileHash-MD5 b143e9814f3ce07fa7176ecdd4dfda89 2025-01-09
FileHash-MD5 b919ab6f54f632401d708c66675da07d 2025-01-09
FileHash-MD5 ba21e11dbaccb64f84191e4f57f137e0 2025-01-09
FileHash-MD5 bf2ca4d4d7ceafb8cd6d7a9cc5ac5d8c 2025-01-09
FileHash-MD5 c3b668cce4dd5a8b88cdf9e1829a3da3 2025-01-09
FileHash-MD5 ccbe1d6e56a70bc67fccd23dac4d650e 2025-01-09
FileHash-MD5 e6a65bccc172345cd69f04d4ef4d5ee0 2025-01-09
FileHash-MD5 e79180380997a855c8d19be02d035b7f 2025-01-09
FileHash-MD5 ed841f0e2e4a322b5e4ba3d514c07dac 2025-01-09
FileHash-MD5 f5f51b41603bf120c4d9cd2f392b6bd6 2025-01-09
FileHash-MD5 f6edc0354c72f0cd37899d25992364e2 2025-01-09
FileHash-MD5 fc997de78ccf709d1f0da8957cbd0a3e 2025-01-09