logo

Back Despite Disruption: RedDelta Resumes Operations

ID: ce995aa6-8658-41d1-825a-44e6a1a44f36

STIX ID: report--ce995aa6-8658-41d1-825a-44e6a1a44f36

Threat Score

82/100

Uploaded: 2026-08-19

Published Date: 2020-09-13

Last Modified Date: 2020-09-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report documents RedDelta, a Chinese state-sponsored threat actor, resuming and expanding its cyberespionage activities using PlugX malware and DLL side-loading against Vatican-related targets, Hong Kong Catholic Diocese mail servers, Myanmar government systems, and Hong Kong universities, with decoy documents themed around Catholicism, Tibet-Ladakh, and UN topics; it describes reused public infrastructure, new C2 domains, a timeline of activity, associated malware artifacts, and recommended mitigations and outlook.