Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Red Nue

Also known as: LuoYu

Description

Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows and Macintosh (reported in open source as Demsty), as well as an Android variant known as SpyDealer. Red Nue has also used another Windows backdoor known as WinDealer since at least 2019, when it deployed it to targets as part of a watering hole campaign on a Chinese news website for the Chinese diaspora community. Parts of Asia feature heavily in Red Nue's victimology.

AI Analysis

· 1 week ago

Executive Summary

Red Nue (LuoYu) is an active cyber threat group known for its sophisticated malware toolkit targeting regions in Asia. They use multiplatform backdoors like LootRAT and WinDealer, and have demonstrated the ability to compromise systems via watering hole attacks. Their activities pose significant risks to targeted sectors through data exfiltration and persistent access.

Goals & Targeting

The goals of Red Nue appear to center around strategic data collection and potential espionage activities, targeting regions and sectors where sensitive information is held. They focus on Asia, possibly with motivations tied to regional political or economic interests. Their choice of watering hole attacks indicates a tactic to compromise trustable sites within target communities, maximizing their effectiveness in infiltrating networks.

Enhanced Description

Red Nue, operating since at least 2017, is primarily known for deploying the multi-platform LootRAT backdoor, which has variants for Windows, Macintosh (referred to as Demsty), and Android (SpyDealer). The group also utilizes WinDealer, a Windows-based backdoor deployed in a 2019 watering hole campaign targeting a Chinese news website frequented by the diaspora community. Red Nue's campaigns indicate a strategic focus on sectors within Asia, suggesting potential interests in espionage or information theft. Their use of advanced malware highlights their technical capabilities and persistence in compromising target systems for long-term access.

Key Capabilities

  • Multi-platform malware deployment
  • Watering hole attack techniques
  • Persistent access via backdoors
  • Sophisticated payload delivery mechanisms

MITRE ATT&CK Tactics

Initial Access
Defense Evasion

ATT&CK Techniques

T1070.003
T1566.001

Software / Tooling

LootRAT
WinDealer
SpyDealer

Campaigns & Victims

Red Nue's campaigns, such as the 2019 attack on a Chinese news website, demonstrate their ability to identify and exploit vulnerabilities in targeted ecosystems. They exhibit patience and strategic planning in compromising high-value targets, indicating a focus on long-term goals rather than quick gains.

IOC Patterns

  • Multi-platform backdoor deployments
  • Watering hole attacks via compromised websites
  • Command and Control (C2) communication channels

Recommended Actions

  • Monitor network traffic for signs of multi-stage attacks
  • Implement strict access controls to critical systems
  • Use endpoint detection solutions to identify known malware signatures
  • Educate users on phishing and malicious document risks
  • Regularly update software to patch vulnerabilities

Suggested Tags

APT
espionage
Asia-Pacific
malware
watering-hole

Confidence Assessment

Moderate confidence is placed in the data describing Red Nue, with known tools and campaign patterns. However, gaps exist regarding their primary motivations, exact target industries, and full range of tactics. Further intelligence collection is needed to fully understand their operational scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
espionage
Asia-Pacific
malware
watering-hole

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.