Threat actor
RedDelta
Last fetched
RedDelta is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 85 techniques.
Description
Likely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX backdoor. Since at least 2019, RedDelta has been consistently active within Southeast Asia, particularly in Myanmar and Vietnam, but has also routinely adapted its targeting in response to global geopolitical events. This is historically evident through the group’s targeting of the Vatican and other Catholic organizations in the lead-up to 2021 talks between Chinese Communist Party (CCP) and Vatican officials, as well as throughout 2022 through the group’s shift towards increased targeting of European government and diplomatic entities following Russia’s invasion of Ukraine. During the 3-month period from September through November 2022, RedDelta has regularly used an infection chain employing malicious shortcut (LNK) files, which trigger a dynamic-link library (DLL) search-order-hijacking execution chain to load consistently updated PlugX versions. Throughout this period, the group repeatedly employed decoy documents specific to government and migration policy within Europe. Of note, we identified a European government department focused on trade communicating with RedDelta command-and-control (C2) infrastructure in early August 2022. This activity commenced on the same day that a RedDelta PlugX sample using this C2 infrastructure and featuring an EU trade-themed decoy document surfaced on public malware repositories. We also identified additional probable victim entities within Myanmar and Vietnam regularly communicating with RedDelta C2 infrastructure. RedDelta closely overlaps with public industry reporting under the aliases BRONZE PRESIDENT, Mustang Panda, TA416, Red Lich, and HoneyMyte.
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1071.001 · Web Protocols
- T1095 · Non-Application Layer Protocol
- T1102 · Web Service
- T1105 · Ingress Tool Transfer
- T1205 · Traffic Signaling
- T1219.001 · IDE Tunneling
- T1219.002 · Remote Desktop Software
- T1572 · Protocol Tunneling
- T1573.001 · Symmetric Cryptography
Discovery
- T1016 · System Network Configuration Discovery
- T1018 · Remote System Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1069.002 · Domain Groups
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1087.002 · Domain Account
- T1518 · Software Discovery
- T1622 · Debugger Evasion
- T1654 · Log Enumeration
Execution
- T1047 · Windows Management Instrumentation
- T1053.005 · Scheduled Task
- T1059 · Command and Scripting Interpreter
- T1059.001 · PowerShell
- T1059.003 · Windows Command Shell
- T1059.005 · Visual Basic
- T1059.007 · JavaScript
- T1072 · Software Deployment Tools
- T1106 · Native API
- T1129 · Shared Modules
- T1203 · Exploitation for Client Execution
- T1204.001 · Malicious Link
- T1204.002 · Malicious File
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
Stealth
- T1027 · Obfuscated Files or Information
- T1027.007 · Dynamic API Resolution
- T1027.012 · LNK Icon Smuggling
- T1027.016 · Junk Code Insertion
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.007 · Double File Extension
- T1036.008 · Masquerade File Type
- T1070 · Indicator Removal
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1140 · Deobfuscate/Decode Files or Information
- T1205 · Traffic Signaling
- T1218.004 · InstallUtil
- T1218.005 · Mshta
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
- T1622 · Debugger Evasion
- T1678 · Delay Execution
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to RedDelta today — this states the absence of a published link, not that RedDelta has no infrastructure.
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from RedDelta into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.