logo

Chinese State-Sponsored RedJuliett Intensifies Taiwanese Government, Academic, and Technology Sector Cyber Espionage via Network Perimeter Exploitation

ID: f60752c5-4daf-4537-a757-28c17c3b39fb

STIX ID: report--f60752c5-4daf-4537-a757-28c17c3b39fb

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2024-06-21

Last Modified Date: 2024-06-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
RedJuliett, a likely Chinese state-sponsored APT, conducted high-tempo cyber-espionage from November 2023–April 2024 focused on Taiwan and surrounding regions by exploiting internet-facing devices (firewalls, load balancers, VPNs) and web/SQL applications, administering infrastructure via SoftEther VPN (with servers and self-signed TLS certificates tied to Fuzhou), and performing reconnaissance, exploitation (SQL injection, directory traversal), and limited post-exploitation using open-source web shells and known vulnerabilities; the report includes victimology, IOCs (IP addresses, TLS fingerprints, domains), ATT&CK mappings, and recommended mitigations for detection and hardening.