Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedAlpha

Also known as: DeepCliff, Red Dev 3

Description

Recorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we are collectively naming RedAlpha, combine light reconnaissance, selective targeting, and diverse malicious tooling. We discovered this activity as the result of pivoting off of a new malware sample observed targeting the Tibetan community based in India.

AI Analysis

· 1 week ago

Executive Summary

RedAlpha is a cyberespionage threat actor targeting the Tibetan community with campaigns observed over the past two years by Insikt Group. The group employs diverse malicious tooling and tactics to gather intelligence, likely focusing on sensitive sectors such as government or non-governmental organizations in India.

Goals & Targeting

RedAlpha's primary motivation appears to be intelligence gathering on the Tibetan community. Targeted sectors likely include government agencies, NGOs, and private entities interacting with Tibetan groups. Countries targeted are mainly India and China, reflecting the geographical focus of affected communities.

Enhanced Description

RedAlpha, also known as DeepCliff and Red Dev 3, has been identified through malware samples targeting the Tibetan community in India. The actor uses a combination of侦察 techniques and selective targeting, leveraging diverse malicious tools to achieve espionage objectives. Campaigns are tailored to collect sensitive information from individuals or organizations interacting with the Tibetan community.

Key Capabilities

  • Custom malware development
  • Spear-phishing campaigns
  • Diverse malicious tooling

MITRE ATT&CK Tactics

Espionage
Data Collection

ATT&CK Techniques

T1566 Spear-Phishing via Email
T1046.configuration信息收集
T1059-Malware infection via document files

Software / Tooling

Custom RAT
C2 Frameworks
Malicious Excel/Word documents

Campaigns & Victims

RedAlpha's campaigns are persistent and tailored, with a focus on evading detection. The actor likely reuses malware frameworks but customizes each campaign to avoid suspicion. Notable operations include multiple waves of phishing attacks targeting specific individuals within the Tibetan community.

IOC Patterns

  • Phishing emails
  • Malicious Office documents
  • Encrypted C2 communication

Recommended Actions

  • Enhance email security filtering
  • Implement user training on phishing识别
  • Monitor network traffic异常情况
  • Use endpoint detection tools for file analysis
  • Share threat intelligence with regional law enforcement

Suggested Tags

APT
espionage
government
NGO
regional Threat

Confidence Assessment

Moderate confidence in RedAlpha's existence and activity due to Insikt Group findings. Gaps include exact TTPs, toolset details beyond malware samples, and potential state sponsorship. Further analysis is needed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
government
NGO
regional Threat

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.