Back Despite Disruption: RedDelta Resumes Operations
ID: ce995aa6-8658-41d1-825a-44e6a1a44f36
STIX ID: report--ce995aa6-8658-41d1-825a-44e6a1a44f36
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2020-09-13
Last Modified Date: 2020-09-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report documents RedDelta, a Chinese state-sponsored threat actor, resuming and expanding its cyberespionage activities using PlugX malware and DLL side-loading against Vatican-related targets, Hong Kong Catholic Diocese mail servers, Myanmar government systems, and Hong Kong universities, with decoy documents themed around Catholicism, Tibet-Ladakh, and UN topics; it describes reused public infrastructure, new C2 domains, a timeline of activity, associated malware artifacts, and recommended mitigations and outlook.
