Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain
ID: a6312cc3-e2b0-48b9-b2b0-4998ab05ebb5
STIX ID: report--a6312cc3-e2b0-48b9-b2b0-4998ab05ebb5
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2025-01-07
Last Modified Date: 2025-01-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future’s Insikt Group documents RedDelta (a Chinese state‑sponsored APT) conducting targeted espionage across Mongolia, Taiwan, Myanmar, Vietnam, Cambodia and other countries from July 2023–Dec 2024. The group evolved its infection chain—using LNK, MSC, and HTML landing pages to stage MSI installers that deploy Nim-based loaders and a customized PlugX backdoor via DLL search-order hijacking—while proxying C2 through Cloudflare (including geofencing). The report includes confirmed compromises (e.g., Mongolian Ministry of Defense), detailed IoCs (domains, IPs, hashes), detection rules (YARA/Sigma), persistence/TTP mappings, and mitigations.
