Also known as: DeepCliff, Red Dev 3
Recorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we are collectively naming RedAlpha, combine light reconnaissance, selective targeting, and diverse malicious tooling. We discovered this activity as the result of pivoting off of a new malware sample observed targeting the Tibetan community based in India.
Executive Summary
RedAlpha is a cyberespionage threat actor targeting the Tibetan community with campaigns observed over the past two years by Insikt Group. The group employs diverse malicious tooling and tactics to gather intelligence, likely focusing on sensitive sectors such as government or non-governmental organizations in India.
Goals & Targeting
RedAlpha's primary motivation appears to be intelligence gathering on the Tibetan community. Targeted sectors likely include government agencies, NGOs, and private entities interacting with Tibetan groups. Countries targeted are mainly India and China, reflecting the geographical focus of affected communities.
Enhanced Description
RedAlpha, also known as DeepCliff and Red Dev 3, has been identified through malware samples targeting the Tibetan community in India. The actor uses a combination of侦察 techniques and selective targeting, leveraging diverse malicious tools to achieve espionage objectives. Campaigns are tailored to collect sensitive information from individuals or organizations interacting with the Tibetan community.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedAlpha's campaigns are persistent and tailored, with a focus on evading detection. The actor likely reuses malware frameworks but customizes each campaign to avoid suspicion. Notable operations include multiple waves of phishing attacks targeting specific individuals within the Tibetan community.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in RedAlpha's existence and activity due to Insikt Group findings. Gaps include exact TTPs, toolset details beyond malware samples, and potential state sponsorship. Further analysis is needed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics