Also known as: Red Dev 18, Earth Bluecrow
Since 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as entities in the government, education, and logistics sectors using a custom backdoor referred as BPFDoor. This threat actor uses a variety of tools in its post-exploitation phase. This includes custom variants of the shared tool Mangzamel (including Golang variants), custom variants of Gh0st, and open source tools like Mimikatz and Metasploit to aid in its lateral movement across Windows systems. Also, They have been seen sending commands to BPFDoor victims via Virtual Privat Servers (VPSs) hosted at a well-known provider, and that these VPSs, in turn, are administered via compromised routers based in Taiwan, which the threat actor uses as VPN tunnels. Most Red Menshen activity that has been observed took place between Monday to Friday (with none observed on the weekends), with most communication taking place between 01:00 and 10:00 UTC.131 This pattern suggests a consistent 8 to 9-hour activity window for the threat actor, with realistic probability of it aligning to local working hours.
Targeted Sectors
Executive Summary
Red Menshen, a China-based threat actor observed since 2021, primarily targets government, education, and transportation sectors in the Middle East and Asia. Known for using a custom backdoor (BPFDoor) and leveraging tools like Gh0st, Mangzamel, and Mimikatz, Red Menshen exhibits sophisticated post-exploitation techniques. Their activities suggest a focus on data collection or espionage, with operations typically conducted during weekdays from 1:00 to 10:00 UTC.
Goals & Targeting
Red Menshen's strategic objectives appear to center on情报收集和网络持久性。The group's targeting of government, education, and transportation sectors suggests a focus on accessing sensitive data or disrupting critical infrastructure. The selection of victims in the Middle East and Asia may reflect regional priorities, potentially aligned with geopolitical interests. The consistent timing of attacks (Monday-Friday, 01:00-10:00 UTC) indicates a structured operational approach, likely aimed at avoiding detection while maintaining access to compromised networks.
Enhanced Description
Red Menshen has emerged as a significant cyber threat targeting critical infrastructure sectors across Asia and the Middle East. The group's primary tool, BPFDoor, is a custom backdoor used to gain persistence and facilitate lateral movement within compromised networks. Red Menshen also employs various tools, including Gh0st for remote control, Mangzamel variants for information theft, and open-source frameworks like Metasploit for exploitation. Notably, the threat actor communicates with victims using Virtual Private Servers (VPSs) hosted in well-known providers, which are themselves controlled via compromised routers located in Taiwan. This multi-layered infrastructure suggests a high level of operational sophistication and an emphasis on evading detection. The group's targeting patterns, focusing on government, education, and transportation sectors, indicate a strategic focus on collecting sensitive information or disrupting critical services. Their activity windows, concentrated between Monday to Friday and during early morning hours (01:00-10:00 UTC), align with operational rhythms that may reflect local working hours, possibly indicating a state-sponsored origin.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Red Menshen's campaign patterns are characterized by a strict adherence to an 8-9 hour operational window during weekdays. The use of compromised routers in Taiwan as intermediaries for VPS-based command and control suggests a focus on obfuscating attack chains. Victimology indicates a preference for sectors with high strategic value, such as government agencies and critical infrastructure providers. Notable past operations include multiple intrusions into Middle Eastern telecommunications firms, where the group likely sought to gather sensitive data or disrupt services.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence exists in Red Menshen's operational profile based on observed TTPs and tool usage. However, gaps remain regarding their exact motivations (e.g., state-sponsored or financially driven) and the full extent of their attack campaigns beyond those publicly reported.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics