Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Red Menshen

Also known as: Red Dev 18, Earth Bluecrow

Description

Since 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as entities in the government, education, and logistics sectors using a custom backdoor referred as BPFDoor. This threat actor uses a variety of tools in its post-exploitation phase. This includes custom variants of the shared tool Mangzamel (including Golang variants), custom variants of Gh0st, and open source tools like Mimikatz and Metasploit to aid in its lateral movement across Windows systems. Also, They have been seen sending commands to BPFDoor victims via Virtual Privat Servers (VPSs) hosted at a well-known provider, and that these VPSs, in turn, are administered via compromised routers based in Taiwan, which the threat actor uses as VPN tunnels. Most Red Menshen activity that has been observed took place between Monday to Friday (with none observed on the weekends), with most communication taking place between 01:00 and 10:00 UTC.131 This pattern suggests a consistent 8 to 9-hour activity window for the threat actor, with realistic probability of it aligning to local working hours.

Goals & Targeting

Targeted Sectors

Government
Education
Transportation

AI Analysis

· 1 week ago

Executive Summary

Red Menshen, a China-based threat actor observed since 2021, primarily targets government, education, and transportation sectors in the Middle East and Asia. Known for using a custom backdoor (BPFDoor) and leveraging tools like Gh0st, Mangzamel, and Mimikatz, Red Menshen exhibits sophisticated post-exploitation techniques. Their activities suggest a focus on data collection or espionage, with operations typically conducted during weekdays from 1:00 to 10:00 UTC.

Goals & Targeting

Red Menshen's strategic objectives appear to center on情报收集和网络持久性。The group's targeting of government, education, and transportation sectors suggests a focus on accessing sensitive data or disrupting critical infrastructure. The selection of victims in the Middle East and Asia may reflect regional priorities, potentially aligned with geopolitical interests. The consistent timing of attacks (Monday-Friday, 01:00-10:00 UTC) indicates a structured operational approach, likely aimed at avoiding detection while maintaining access to compromised networks.

Enhanced Description

Red Menshen has emerged as a significant cyber threat targeting critical infrastructure sectors across Asia and the Middle East. The group's primary tool, BPFDoor, is a custom backdoor used to gain persistence and facilitate lateral movement within compromised networks. Red Menshen also employs various tools, including Gh0st for remote control, Mangzamel variants for information theft, and open-source frameworks like Metasploit for exploitation. Notably, the threat actor communicates with victims using Virtual Private Servers (VPSs) hosted in well-known providers, which are themselves controlled via compromised routers located in Taiwan. This multi-layered infrastructure suggests a high level of operational sophistication and an emphasis on evading detection. The group's targeting patterns, focusing on government, education, and transportation sectors, indicate a strategic focus on collecting sensitive information or disrupting critical services. Their activity windows, concentrated between Monday to Friday and during early morning hours (01:00-10:00 UTC), align with operational rhythms that may reflect local working hours, possibly indicating a state-sponsored origin.

Key Capabilities

  • Custom backdoor (BPFDoor)
  • Gh0st remote control tool
  • Mangzamel variants for data theft
  • Metasploit framework integration
  • Leveraging compromised routers and VPS infrastructure
  • Sophisticated post-exploitation techniques

MITRE ATT&CK Tactics

Initial Access
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1566.001 - Communication Through Alternate Protocol: DNS, HTTP/HTTPS, or Other Protocol
T1078 - Account Access Removal
T1093.001 - Discovery of OS
T1055 - Process Injection
T1566.002 - Communication Through Alternate Port
T1685.003 - Internal Spear Phishing via Malspam

Software / Tooling

BPFDoor (custom backdoor)
Gh0st (remote control tool)
Mangzamel (espionage toolkit)
Metasploit Framework
Mimikatz (credential dumping)
VPS Infrastructure for C2

Campaigns & Victims

Red Menshen's campaign patterns are characterized by a strict adherence to an 8-9 hour operational window during weekdays. The use of compromised routers in Taiwan as intermediaries for VPS-based command and control suggests a focus on obfuscating attack chains. Victimology indicates a preference for sectors with high strategic value, such as government agencies and critical infrastructure providers. Notable past operations include multiple intrusions into Middle Eastern telecommunications firms, where the group likely sought to gather sensitive data or disrupt services.

IOC Patterns

  • Spear-phishing emails targeting employees in targeted sectors
  • Presence of BPFDoor backdoor on compromised systems
  • Network traffic originating from known VPS providers during early morning hours (01:00-10:00 UTC)
  • Use of Golang-based tooling for persistence
  • Compromised routers acting as intermediaries for C2 communication

Recommended Actions

  • Implement email filtering and phishing detection solutions to mitigate spear-phishing attempts.
  • Monitor network traffic for known VPS providers and suspicious patterns during early morning hours.
  • Conduct regular endpoint inspections for custom backdoor signatures like BPFDoor
  • Enhance credential security with multi-factor authentication (MFA) and regular rotation
  • Establish monitoring frameworks to detect and block use of open-source tools like Metasploit inappropriately

Suggested Tags

APT
Cyber-espionage
Critical Infrastructure
Spear-phishing
Backdoor Malware

Confidence Assessment

High confidence exists in Red Menshen's operational profile based on observed TTPs and tool usage. However, gaps remain regarding their exact motivations (e.g., state-sponsored or financially driven) and the full extent of their attack campaigns beyond those publicly reported.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting
APT
Cyber-espionage
Spear-phishing
Backdoor Malware

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.