Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group. RedGolf closely overlaps with threat activity reported in open sources under the aliases APT41/BARIUM and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward.
Targeted Sectors
Executive Summary
RedGolf is a high-sophistication cyber threat group attributed to Chinese state-sponsored activity. Known for dual-motivations of espionage and financial gain, RedGolf operates across sectors including education, government, media, and IT, leveraging custom backdoors like KEYPLUG. This group poses significant risks to data integrity and national security.
Goals & Targeting
RedGolf's strategic objectives appear to include state-sponsored espionage alongside financially driven operations. The group primarily targets sectors that hold sensitive information such as education, government, media, and IT. Their victims are often organizations with access to valuable data or resources that can be exploited for both intelligence and economic gain.
Enhanced Description
RedGolf is a cyber threat actor tracked by Recorded Future's Insikt Group, identified through extensive operational infrastructure linked to the use of the KEYPLUG backdoor tool. The group is highly likely to be Chinese state-sponsored, with activity overlapping APT41/BARIUM since at least 2014. RedGolf engages in both espionage and financially motivated operations, targeting sectors critical for intelligence gathering and financial gain. Their activities suggest a well-organized structure capable of complex attacks, while their dual motivations make them particularly versatile in attack vectors and targets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedGolf's campaigns are characterized by long-term, stealthy operations leveraging custom malware and sophisticated attack vectors. The group has demonstrated the ability to persistently target multiple industries while maintaining a low profile. Notable for dual-motivations, RedGolf balances state-sponsored espionage with financially driven activities, making their operations diverse and challenging to detect.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the attribution to a Chinese state-sponsored actor, though specific campaign details remain limited. Further intelligence sharing could enhance understanding of operational patterns and TTPs.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics