In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat actor. Their analysis suggests Red Dev 17 has been active since at least 2017. Red Dev 17's observed targets are mainly in India, and include the Indian military, a multinational India-based technology company, and a state energy company. They assess that it is highly probable that the threat actor behind intrusions associated with Red Dev 17 is also responsible for the campaign known in open source as Operation NightScout. Red Dev 17 is a user of the 8.t document weaponisation framework (also known as RoyalRoad), and abuses benign utilities such as Logitech or Windows Defender binaries to sideload and execute Chinoxy or PoisonIvy variants on victim systems. They identified capability and infrastructure links between Red Dev 17 and the threat actor they call Red Hariasa (aka FunnyDream APT), as well as infrastructure overlaps with Red Wendigo (aka Icefog, RedFoxtrot), and with ShadowPad C2 servers. At this time, they do not have sufficient evidence to directly link Red Dev 17 to any of these threat actors. However, They assess with realistic probability that Red Dev 17 operates within a cluster of threat actors that share tools and infrastructure, as well as a strong targeting focus on Southeast Asia and Central Asia.
Targeted Sectors
Executive Summary
Red Dev 17 is assessed by PwC as a likely China-based threat actor targeting defense and energy sectors, particularly in India. They are linked to the Operation NightScout campaign and employ sophisticated tactics such as document weaponization and benign utility abuse for lateral movement.
Goals & Targeting
Red Dev 17's strategic objectives likely include intelligence gathering and potential military or economic advantage, given their focus on defense and energy sectors in India and other Asian countries. The actor's targeting profile suggests a focus on state-owned enterprises and critical infrastructure, aligning with common motivations for Advanced Persistent Threat (APT) groups.
Enhanced Description
Red Dev 17 has been tracked since at least 2017 by PwC, with activity observed primarily targeting India's military, technology companies, and energy sectors. The actor is known to use the 8.t document weaponisation framework (also referred to as RoyalRoad) and has been observed abusing legitimate tools like Logitech and Windows Defender binaries to sideload and execute Chinoxy or PoisonIvy variants on compromised systems. Notably, Red Dev 17 exhibits operational similarities with other suspected Chinese-speaking threat actors, including Red Hariasa (FunnyDream APT), Red Wendigo (Icefog, RedFoxtrot), and ShadowPad C2 servers, though no direct link has been established. Their targeting focus appears to be concentrated on Southeast Asia and Central Asia, aligning with broader regional cyber espionage trends.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Red Dev 17 has been observed in several campaigns targeting Indian military and energy sectors. Their activity overlaps with other suspected Chinese-speaking APTs, suggesting a potential shared operational framework. Notable campaign patterns include the use of document-based attacks and lateral movement techniques. The actor's long-term activity since at least 2017 indicates a sustained interest in their target regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment of Red Dev 17 as a China-based threat actor is based on PwC's analysis and overlaps with known APT behaviors. However, the lack of direct evidence linking them to other actors (e.g., Red Hariasa or Red Wendigo) introduces some uncertainty. Additional intelligence on their exact motivations and long-term goals would enhance confidence in this assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics