Security USA

Recorded Future: Threat Activity Group RedFoxtrot Linked to Chinese Military

Research Provides End-to-End Glimpse Into People’s Liberation Army (PLA) Cyber Operations

Recorded Future, the world’s largest provider of intelligence for enterprise security, today revealed cyber espionage activity attributed to a suspected Chinese state-sponsored threat activity group, named RedFoxtrot by Recorded Future’s threat research arm Insikt Group, in a new report. Insikt Group identified specific ties between RedFoxtrot’s activity and the Chinese military intelligence apparatus, the People’s Liberation Army (PLA) Unit 69010 within the Strategic Support Force (SSF), offering a rare glimpse into SSF operations since the PLA’s restructuring in 2015. 

Recorded Future’s large-scale, automated network traffic analytics and expert analysis detected intrusions targeting sectors across bordering Asian countries. Key findings from the report include: 

·  Active since 2014, RedFoxtrot predominantly targets aerospace and defense, government, telecommunications, mining, and research organizations in Afghanistan, India, Kazakhstan, Kyrgyzstan, Pakistan, Tajikistan, and Uzbekistan, aligning with the operational remit of PLA Unit 69010. 

·  RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyber espionage groups.

·  RedFoxtrot activity overlaps with threat groups tracked by other security vendors such as Temp.Trident and Nomad Panda.

·  It is assessed with high confidence that RedFoxtrot is a Chinese state-sponsored threat activity group based on identified links to a specific PLA unit and the use of shared custom capabilities considered unique to Chinese cyber espionage groups.

“The recent activity of the People’s Liberation Army has largely been a black box for the intelligence community. Being able to provide this rare end-to-end glimpse into PLA activity and Chinese military tactics and motivations provides invaluable insight into the global threat landscape. The persistent and pervasive monitoring and collection of intelligence is crucial in order to disrupt adversaries and inform an organization or government’s security posture.” — Dr. Christopher Ahlberg, CEO and Co-Founder, Recorded Future

To access the full report, visit: Threat Activity Group RedFoxtrot Linked to China’s PLA Unit 69010; Targets Bordering Asian Countries

Related posts

Skylark Opens OT Cybersecurity COE with Fortinet

enterpriseitworld

Dynatrace Joins the Microsoft Intelligent Security Association

enterpriseitworld

Exabeam and Wiz Partner to Strengthen Cloud Security Threat Detection

enterpriseitworld
x