Redjuliett

Threat Actor updated 25 days ago (2024-08-14T09:49:05.907Z)
Download STIX
Preview STIX
RedJuliett, a Chinese state-sponsored threat group, has been implicated in persistent espionage attacks on approximately 75 organizations since 2023. This information was reported by Insikt Group, the threat research arm of Recorded Future. The targeted organizations span across government, academic, and technology sectors in various countries. RedJuliett's modus operandi includes exploiting vulnerabilities in network edge devices such as firewalls, virtual private networks, and load balancers to gain initial access. The group also leverages an open-source VPN client, SoftEther, to target infrastructures. Taiwan is currently grappling with a surge of cyber-espionage attacks from RedJuliett. As of June 24th, the group has attacked 24 different Taiwanese government agencies, educational institutions, and technology firms. The activities of RedJuliett align with China's strategic objectives to gather intelligence on Taiwan's economic policy, trade, and diplomatic relations. The group has also compromised organizations in Laos, Kenya, and Rwanda. Furthermore, RedJuliett is known to overlap with other threat groups known as Flax Typhoon and Ethereal Panda. Insikt Group predicts that RedJuliett and other Chinese state-sponsored threat actors will persistently target Taiwan for intelligence gathering, focusing on universities, government organizations, think tanks, and technology companies. RedJuliett operates its infrastructure using SoftEther VPN, utilizing both threat actor-controlled leased servers and compromised infrastructure belonging to Taiwanese universities. In addition to exploiting vulnerabilities in internet-facing devices, the group also uses SQL injection and directory traversal exploits against web and SQL applications. It is recommended to monitor Malicious Traffic Analysis (MTA) to proactively detect and alert on infrastructure communicating with known RedJuliett command-and-control (C2) IP addresses.
Description last updated: 2024-08-14T09:11:34.823Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Flax Typhoon
2
Flax Typhoon, a threat actor linked to China, has been identified as the perpetrator behind a series of cyber attacks targeting Taiwan. The group is known for its unique approach, utilizing minimal malware and custom payloads, but heavily relying on legitimate applications instead. This tactic allow
Ethereal Panda
2
Ethereal Panda, also known as Flax Typhoon, is a threat actor believed to be based in China. The activities of this group strongly overlap with those reported under the aliases Flax Typhoon by Microsoft and Ethereal Panda by CrowdStrike. This correlation suggests that Ethereal Panda operates as a na
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
State Sponso...
Exploit
Vpn
Taiwan
Source
Chinese
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Redjuliett Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
BankInfoSecurity
2 months ago
Australia Flags Persistent Chinese Cyberespionage Hacking
Recorded Future
2 months ago
Chinese State-Sponsored RedJuliett Intensifies Taiwanese Cyber Espionage via Network Perimeter Exploitation | Recorded Future
DARKReading
2 months ago
China-Linked Espionage Groups Target Asian Telecoms
BankInfoSecurity
2 months ago
Chinese Hackers Caught Spying on Taiwanese Firms
InfoSecurity-magazine
2 months ago
China-Based RedJuliett Targets Taiwan in Cyber Espionage Campaign
Recorded Future
2 months ago
Chinese State-Sponsored RedJuliett Intensifies Taiwanese Cyber Espionage via Network Perimeter Exploitation | Recorded Future