Chinese State-Sponsored RedJuliett Intensifies Taiwanese Government, Academic, and Technology Sector Cyber Espionage via Network Perimeter Exploitation
ID: f60752c5-4daf-4537-a757-28c17c3b39fb
STIX ID: report--f60752c5-4daf-4537-a757-28c17c3b39fb
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2024-06-21
Last Modified Date: 2024-06-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
RedJuliett, a likely Chinese state-sponsored APT, conducted high-tempo cyber-espionage from November 2023–April 2024 focused on Taiwan and surrounding regions by exploiting internet-facing devices (firewalls, load balancers, VPNs) and web/SQL applications, administering infrastructure via SoftEther VPN (with servers and self-signed TLS certificates tied to Fuzhou), and performing reconnaissance, exploitation (SQL injection, directory traversal), and limited post-exploitation using open-source web shells and known vulnerabilities; the report includes victimology, IOCs (IP addresses, TLS fingerprints, domains), ATT&CK mappings, and recommended mitigations for detection and hardening.
