news.mlab.sh
Threat intelligence
Threat actor

RedHotel

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2021-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aerospace, Education, Government, Media, Telecommunications
TLP
WHITE

(Recorded Future) Recorded Future has identified a suspected Chinese state-sponsored group that we track as Threat Activity Group 22 (TAG-22) targeting telecommunications, academia, research and development, and government organizations in Nepal, the Philippines, Taiwan, and more historically, Hong Kong. In this most recent activity, the group likely used compromised GlassFish servers and Cobalt Strike in initial access operations before switching to the bespoke Winnti, ShadowPad, and Spyder backdoors for long-term access using dedicated actor-provisioned command and control infrastructure. Also see Earth Lusca.

Also known as

FishmongerRedHotelTAG-22

Coverage 5