Threat Activity Group RedFoxtrot Linked to China’s PLA Unit 69010; Targets Bordering Asian Countries
ID: d1c0b68e-ad62-4232-8be3-8bb13c1b2583
STIX ID: report--d1c0b68e-ad62-4232-8be3-8bb13c1b2583
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-06-15
Last Modified Date: 2021-06-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group links the China-aligned threat activity group "RedFoxtrot" to PLA Unit 69010, presenting network traffic analysis, infrastructure fingerprinting, and ties to known malware families (PCShare, PlugX, IceFog, Poison Ivy, Royal Road, ShadowPad). The report documents targeting of defense, government, and telecommunications across Central and South Asia (notably India, Pakistan, Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan), provides extensive IoCs (domains, IPs, malware hashes), historical campaign overlaps (SKYLINE, WATERFIGHT), forensic malware analysis, and mitigation recommendations for detection and blocking.
