Redjuliett

Threat Actor updated a month ago (2024-09-26T20:01:06.871Z)
Download STIX
Preview STIX
RedJuliett, a Chinese state-sponsored threat actor group, has been identified as the perpetrator behind persistent espionage attacks on approximately 75 organizations since 2023. These organizations span multiple sectors including government, academic, and technology across various countries. The group is believed to be under the control of the China-linked APT group Flax Typhoon, also known as Ethereal Panda. RedJuliett leverages an open-source VPN client, SoftEther, to target these organizations' infrastructures. In Taiwan, RedJuliett has launched a series of attacks against 24 different entities such as government agencies, educational institutions, and technology firms. This includes an optoelectronics company, a facial recognition company, a waste and pollution treatment company, a publishing house, three universities, and four software companies. These attacks occurred between November 2023 and April 2024, aligning with Beijing's objectives to gather intelligence on Taiwan’s economic policy, trade, and diplomatic relations. According to the Insikt Group, the threat research arm of Recorded Future, it is anticipated that RedJuliett and other Chinese state-sponsored threat actors will continue to target Taiwan for intelligence-gathering purposes, focusing particularly on universities, government organizations, think tanks, and technology companies. To administer its operational infrastructure, RedJuliett uses the SoftEther VPN, leveraging both threat actor-controlled leased servers and compromised infrastructure belonging to Taiwanese universities. Monitoring Malicious Traffic Analysis (MTA) can aid in proactively detecting and alerting on infrastructure communicating with known RedJuliett command-and-control (C2) IP addresses.
Description last updated: 2024-09-26T19:18:00.892Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Flax Typhoon is a possible alias for Redjuliett. Flax Typhoon, also known as RedJuliett and Ethereal Panda, is a threat actor linked to China that has been actively targeting entities in Taiwan and around the South China Sea. The group's activities have primarily focused on organizations associated with IT, military, and government interests. Over
3
Ethereal Panda is a possible alias for Redjuliett. Ethereal Panda, also known as Flax Typhoon or RedJuliett, is a threat actor believed to be linked to the Chinese government. This group has been involved in various cyber espionage activities targeting organizations primarily in Taiwan. Reports from cybersecurity firms such as Microsoft and CrowdStr
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
State Sponso...
Exploit
Vpn
Taiwan
Chinese
Source
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Redjuliett Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more