Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedJuliett

Also known as: other aliases, Jumpy Pisces, Onyx Sleet, several other aliases, ALPHV, Gleaming Pisces, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Carbon Spider, Sangria Tempest, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, APT36, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Turbine Panda, Hippo Team, JerseyMikes, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, T-APT-04, Magecart Group 4, India

Description

RedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in Taiwan. They exploit vulnerabilities in network edge devices for initial access and use SQL injection and directory traversal exploits against web and SQL applications. The group operates from Fuzhou, China, and aims to support Beijing's intelligence collection on Taiwan's economic and diplomatic relations. RedJuliett has also expanded its operations to compromise organizations in other countries such as Hong Kong, Malaysia, and the United States.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Education
Healthcare
Critical infrastructure
Manufacturing
Media
Aerospace
Energy
Transportation
Pharmaceutical
Aviation
Think tank
Maritime
Information technology
Utilities
Construction
Hospitality
Non profit
Gaming
Legal services
Retail
Mining
Nuclear
Aerospace & defense
Legal

Targeted Countries / Regions

TW
CN
RU
US
IN
IR
KR
UA
BR
KP
TR
JP
VN
IL
EG
IT
BY

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Command & Control
1 technique
Exfiltration
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 9 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. www.recordedfuture.com — Cited by web research for: T1190
  3. attack.mitre.org — Cited by web research for: T1548
  4. www.huntress.com — Cited by web research for: phishing
  5. ics-cert.kaspersky.com — Cited by web research for: Kapeka

Intel Summary

40

Techniques

67

Tools

7

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Government Targeting

Details

MITRE ID
APT26
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.