Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedGolf

Description

Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group. RedGolf closely overlaps with threat activity reported in open sources under the aliases APT41/BARIUM and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward.

Goals & Targeting

Targeted Sectors

Education
Government
Media
Information technology

AI Analysis

· 1 week ago

Executive Summary

RedGolf is a high-sophistication cyber threat group attributed to Chinese state-sponsored activity. Known for dual-motivations of espionage and financial gain, RedGolf operates across sectors including education, government, media, and IT, leveraging custom backdoors like KEYPLUG. This group poses significant risks to data integrity and national security.

Goals & Targeting

RedGolf's strategic objectives appear to include state-sponsored espionage alongside financially driven operations. The group primarily targets sectors that hold sensitive information such as education, government, media, and IT. Their victims are often organizations with access to valuable data or resources that can be exploited for both intelligence and economic gain.

Enhanced Description

RedGolf is a cyber threat actor tracked by Recorded Future's Insikt Group, identified through extensive operational infrastructure linked to the use of the KEYPLUG backdoor tool. The group is highly likely to be Chinese state-sponsored, with activity overlapping APT41/BARIUM since at least 2014. RedGolf engages in both espionage and financially motivated operations, targeting sectors critical for intelligence gathering and financial gain. Their activities suggest a well-organized structure capable of complex attacks, while their dual motivations make them particularly versatile in attack vectors and targets.

Key Capabilities

  • Custom Windows and Linux backdoors (KEYPLUG)
  • Spear-phishing campaigns
  • Social engineering techniques
  • Persistence mechanisms
  • Data exfiltration

MITRE ATT&CK Tactics

Espionage (TA0027)
Criminal (TA0028)

ATT&CK Techniques

T1055
T1062

Software / Tooling

KEYPLUG
Phishing Kits

Campaigns & Victims

RedGolf's campaigns are characterized by long-term, stealthy operations leveraging custom malware and sophisticated attack vectors. The group has demonstrated the ability to persistently target multiple industries while maintaining a low profile. Notable for dual-motivations, RedGolf balances state-sponsored espionage with financially driven activities, making their operations diverse and challenging to detect.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • Use of custom backdoors for persistence and data exfiltration
  • Lateral movement across compromised networks

Recommended Actions

  • Patch systems against known vulnerabilities related to the KEYPLUG backdoor.
  • Implement Endpoint Detection and Response (EDR) solutions to detect malicious processes and behaviors linked to RedGolf's TTPs.
  • Use email filtering and threat detection solutions to uncover phishing attempts with macro-laced attachments.
  • Monitor network traffic for signs of unauthorized exfiltration or lateral movement consistent with RedGolf campaigns.

Suggested Tags

State-sponsored
Cyberespionage
Criminal
Education sector

Confidence Assessment

High confidence in the attribution to a Chinese state-sponsored actor, though specific campaign details remain limited. Further intelligence sharing could enhance understanding of operational patterns and TTPs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
State-sponsored
Cyberespionage
Criminal
Education sector

Details

Type
Criminal
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.