logo

With KEYPLUG, China’s RedGolf Spies On, Steals From Wide Field of Targets

ID: 9e9ea6f0-a25f-4011-a824-fed9ed598e13

STIX ID: report--9e9ea6f0-a25f-4011-a824-fed9ed598e13

Threat Score

88/100

Uploaded: 2026-08-11

Published Date: 2023-03-29

Last Modified Date: 2023-03-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group attributes extensive KEYPLUG backdoor activity and a GhostWolf infrastructure cluster to RedGolf (likely Chinese state‑sponsored, overlapping with APT41/BARIUM), documenting campaigns from 2021–2023 that targeted US state governments and multiple industry sectors. The report provides detailed malware sample hashes, C2 protocols and IPs, DDNS and domain tradecraft, Cobalt Strike and PlugX usage, hosting provider patterns, a full Appendix of IOCs, and recommended mitigations.