RedAlpha Conducts Multi-Year Credential Theft Campaign Targeting Global Humanitarian, Think Tank, and Government Organizations
ID: c038ac37-ae5f-4d3b-83b1-94f9a03e6ad4
STIX ID: report--c038ac37-ae5f-4d3b-83b1-94f9a03e6ad4
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2022-08-15
Last Modified Date: 2022-08-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Threat Analysis by Recorded Future's Insikt Group documents RedAlpha, a likely Chinese state-sponsored actor, conducting multi-year credential-theft campaigns against humanitarian and government organizations worldwide, using mass infrastructure, typosquatting domains, and credential-phishing pages impersonating trusted services, with notable focus on Taiwan and a potential link to private contractor activity, and it provides mitigations.
