RedDelta Targets European Government Organizations and Continues to Iterate Custom PlugX Variant
ID: bf2b8c7a-2a73-40fd-9f3e-b98edd8c065d
STIX ID: report--bf2b8c7a-2a73-40fd-9f3e-b98edd8c065d
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2022-12-22
Last Modified Date: 2022-12-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group attributes a series of targeted espionage campaigns (Aug–Nov 2022) to the likely Chinese state-sponsored group RedDelta, which deployed a heavily modified PlugX RAT via malicious LNK/ISO delivery and DLL search-order hijacking. The report documents evolving payload encoding, decoy documents themed on European trade and migration, extracted PlugX configs and many IOCs (IP addresses, domains, and file hashes), maps techniques to MITRE ATT&CK, and provides mitigations for network and host defenders.
