logo

Threat Activity Group RedFoxtrot Linked to China’s PLA Unit 69010; Targets Bordering Asian Countries

ID: d1c0b68e-ad62-4232-8be3-8bb13c1b2583

STIX ID: report--d1c0b68e-ad62-4232-8be3-8bb13c1b2583

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-06-15

Last Modified Date: 2021-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group links the China-aligned threat activity group "RedFoxtrot" to PLA Unit 69010, presenting network traffic analysis, infrastructure fingerprinting, and ties to known malware families (PCShare, PlugX, IceFog, Poison Ivy, Royal Road, ShadowPad). The report documents targeting of defense, government, and telecommunications across Central and South Asia (notably India, Pakistan, Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan), provides extensive IoCs (domains, IPs, malware hashes), historical campaign overlaps (SKYLINE, WATERFIGHT), forensic malware analysis, and mitigation recommendations for detection and blocking.