logo

Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain

ID: a6312cc3-e2b0-48b9-b2b0-4998ab05ebb5

STIX ID: report--a6312cc3-e2b0-48b9-b2b0-4998ab05ebb5

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2025-01-07

Last Modified Date: 2025-01-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future’s Insikt Group documents RedDelta (a Chinese state‑sponsored APT) conducting targeted espionage across Mongolia, Taiwan, Myanmar, Vietnam, Cambodia and other countries from July 2023–Dec 2024. The group evolved its infection chain—using LNK, MSC, and HTML landing pages to stage MSI installers that deploy Nim-based loaders and a customized PlugX backdoor via DLL search-order hijacking—while proxying C2 through Cloudflare (including geofencing). The report includes confirmed compromises (e.g., Mongolian Ministry of Defense), detailed IoCs (domains, IPs, hashes), detection rules (YARA/Sigma), persistence/TTP mappings, and mitigations.