Also known as: LuoYu
Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows and Macintosh (reported in open source as Demsty), as well as an Android variant known as SpyDealer. Red Nue has also used another Windows backdoor known as WinDealer since at least 2019, when it deployed it to targets as part of a watering hole campaign on a Chinese news website for the Chinese diaspora community. Parts of Asia feature heavily in Red Nue's victimology.
Executive Summary
Red Nue (LuoYu) is an active cyber threat group known for its sophisticated malware toolkit targeting regions in Asia. They use multiplatform backdoors like LootRAT and WinDealer, and have demonstrated the ability to compromise systems via watering hole attacks. Their activities pose significant risks to targeted sectors through data exfiltration and persistent access.
Goals & Targeting
The goals of Red Nue appear to center around strategic data collection and potential espionage activities, targeting regions and sectors where sensitive information is held. They focus on Asia, possibly with motivations tied to regional political or economic interests. Their choice of watering hole attacks indicates a tactic to compromise trustable sites within target communities, maximizing their effectiveness in infiltrating networks.
Enhanced Description
Red Nue, operating since at least 2017, is primarily known for deploying the multi-platform LootRAT backdoor, which has variants for Windows, Macintosh (referred to as Demsty), and Android (SpyDealer). The group also utilizes WinDealer, a Windows-based backdoor deployed in a 2019 watering hole campaign targeting a Chinese news website frequented by the diaspora community. Red Nue's campaigns indicate a strategic focus on sectors within Asia, suggesting potential interests in espionage or information theft. Their use of advanced malware highlights their technical capabilities and persistence in compromising target systems for long-term access.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Red Nue's campaigns, such as the 2019 attack on a Chinese news website, demonstrate their ability to identify and exploit vulnerabilities in targeted ecosystems. They exhibit patience and strategic planning in compromising high-value targets, indicating a focus on long-term goals rather than quick gains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence is placed in the data describing Red Nue, with known tools and campaign patterns. However, gaps exist regarding their primary motivations, exact target industries, and full range of tactics. Further intelligence collection is needed to fully understand their operational scope.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics