Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Red Dev 17

Description

In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat actor. Their analysis suggests Red Dev 17 has been active since at least 2017. Red Dev 17's observed targets are mainly in India, and include the Indian military, a multinational India-based technology company, and a state energy company. They assess that it is highly probable that the threat actor behind intrusions associated with Red Dev 17 is also responsible for the campaign known in open source as Operation NightScout. Red Dev 17 is a user of the 8.t document weaponisation framework (also known as RoyalRoad), and abuses benign utilities such as Logitech or Windows Defender binaries to sideload and execute Chinoxy or PoisonIvy variants on victim systems. They identified capability and infrastructure links between Red Dev 17 and the threat actor they call Red Hariasa (aka FunnyDream APT), as well as infrastructure overlaps with Red Wendigo (aka Icefog, RedFoxtrot), and with ShadowPad C2 servers. At this time, they do not have sufficient evidence to directly link Red Dev 17 to any of these threat actors. However, They assess with realistic probability that Red Dev 17 operates within a cluster of threat actors that share tools and infrastructure, as well as a strong targeting focus on Southeast Asia and Central Asia.

Goals & Targeting

Targeted Sectors

Defense
Energy

AI Analysis

· 1 week ago

Executive Summary

Red Dev 17 is assessed by PwC as a likely China-based threat actor targeting defense and energy sectors, particularly in India. They are linked to the Operation NightScout campaign and employ sophisticated tactics such as document weaponization and benign utility abuse for lateral movement.

Goals & Targeting

Red Dev 17's strategic objectives likely include intelligence gathering and potential military or economic advantage, given their focus on defense and energy sectors in India and other Asian countries. The actor's targeting profile suggests a focus on state-owned enterprises and critical infrastructure, aligning with common motivations for Advanced Persistent Threat (APT) groups.

Enhanced Description

Red Dev 17 has been tracked since at least 2017 by PwC, with activity observed primarily targeting India's military, technology companies, and energy sectors. The actor is known to use the 8.t document weaponisation framework (also referred to as RoyalRoad) and has been observed abusing legitimate tools like Logitech and Windows Defender binaries to sideload and execute Chinoxy or PoisonIvy variants on compromised systems. Notably, Red Dev 17 exhibits operational similarities with other suspected Chinese-speaking threat actors, including Red Hariasa (FunnyDream APT), Red Wendigo (Icefog, RedFoxtrot), and ShadowPad C2 servers, though no direct link has been established. Their targeting focus appears to be concentrated on Southeast Asia and Central Asia, aligning with broader regional cyber espionage trends.

Key Capabilities

  • Document weaponization using the 8.t framework
  • Abuse of legitimate utilities like Logitech and Windows Defender binaries
  • Spear-phishing campaigns
  • Use of Chinoxy and PoisonIvy malware variants
  • Lateral movement techniques

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1059.003
T1046.004
T1204
T1566.001

Software / Tooling

8.t (RoyalRoad)
Chinoxy
PoisonIvy
Logitech binaries
Windows Defender binaries

Campaigns & Victims

Red Dev 17 has been observed in several campaigns targeting Indian military and energy sectors. Their activity overlaps with other suspected Chinese-speaking APTs, suggesting a potential shared operational framework. Notable campaign patterns include the use of document-based attacks and lateral movement techniques. The actor's long-term activity since at least 2017 indicates a sustained interest in their target regions.

IOC Patterns

  • Spear-phishing emails with malicious documents
  • Use of legitimate binaries for malicious activities
  • Network traffic indicative of C2 servers (e.g., ShadowPad)
  • Document weaponization frameworks (8.t)

Recommended Actions

  • Implement strict document review policies and use endpoint detection tools to identify suspicious file activity.
  • Monitor for abuse of legitimate utilities like Logitech or Windows Defender binaries.
  • Enhance network monitoring for known C2 infrastructure patterns linked to Red Dev 17 and related APTs.
  • Conduct regular employee training on phishing awareness and document safety.

Suggested Tags

APT
espionage
Southeast Asia
China-based
energy sector

Confidence Assessment

The assessment of Red Dev 17 as a China-based threat actor is based on PwC's analysis and overlaps with known APT behaviors. However, the lack of direct evidence linking them to other actors (e.g., Red Hariasa or Red Wendigo) introduces some uncertainty. Additional intelligence on their exact motivations and long-term goals would enhance confidence in this assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting
APT
espionage
Southeast Asia
China-based
energy sector

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.