With KEYPLUG, China’s RedGolf Spies On, Steals From Wide Field of Targets
ID: 9e9ea6f0-a25f-4011-a824-fed9ed598e13
STIX ID: report--9e9ea6f0-a25f-4011-a824-fed9ed598e13
Threat Score
88/100
Uploaded: 2026-08-11
Published Date: 2023-03-29
Last Modified Date: 2023-03-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group attributes extensive KEYPLUG backdoor activity and a GhostWolf infrastructure cluster to RedGolf (likely Chinese state‑sponsored, overlapping with APT41/BARIUM), documenting campaigns from 2021–2023 that targeted US state governments and multiple industry sectors. The report provides detailed malware sample hashes, C2 protocols and IPs, DDNS and domain tradecraft, Cobalt Strike and PlugX usage, hosting provider patterns, a full Appendix of IOCs, and recommended mitigations.
