Redfly

Threat Actor updated 6 months ago (2024-05-04T20:43:29.598Z)
Download STIX
Preview STIX
RedFly, a threat actor group known for its malicious activities, has emerged as a significant cybersecurity concern. The group's operations are characterized by their strategic execution and targeted focus, often resulting in substantial security breaches. Threat actors like RedFly pose a significant risk due to their capacity to infiltrate complex systems, potentially causing severe damage and disruption. The group recently executed a noteworthy attack on an Asian national grid, demonstrating the sophistication of their methods. This infiltration was not a brief operation; instead, it was a long-term breach that lasted approximately six months. The duration of this attack underscores RedFly's ability to maintain a persistent presence within compromised systems, which can lead to extensive data theft or operational disruption. This incident is a stark reminder of the ongoing threats posed by such threat actors in the cybersecurity landscape. It emphasizes the need for robust security measures and constant vigilance to detect and counteract such sophisticated attacks. With threat actors like RedFly continuously evolving their tactics, it is crucial for organizations, particularly those managing critical infrastructure like national grids, to regularly review and update their security protocols.
Description last updated: 2024-03-17T13:22:31.194Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Blackfly is a possible alias for Redfly. Blackfly is a threat actor, tracked by Symantec, that has been involved in cyber-attacks primarily targeting South Korean companies, especially those in the video game and software development industry. The group initiated its activities with a campaign to steal certificates, which were later utiliz
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Trojan
Apt
Espionage
Symantec
Windows
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The ShadowPad Malware is associated with Redfly. ShadowPad is a malicious software (malware) that has been in use since at least 2017, particularly among Chinese threat actors. This modular backdoor malware is designed to exploit and damage computer systems by stealing personal information, disrupting operations, or holding data for ransom. It typUnspecified
5
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The threatActor Greyfly is associated with Redfly. Unspecified
2
The APT41 Threat Actor is associated with Redfly. APT41, also known as Winnti, Wicked Panda, and Brass Typhoon, is a threat actor suspected to be linked to China. This group has been active since at least 2012 and has targeted organizations in over 14 countries. They have used a variety of sophisticated techniques and malware, including at least 46Unspecified
2
Source Document References
Information about the Redfly Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
2 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
8 months ago
Securityaffairs
8 months ago