Red Scylla is a public threat-tracking name associated with cyber operations attributed to China’s state-linked information security contractor ecosystem, particularly activity tied to Anxun Information Technology Co., Ltd. (i-Soon). It is one of several aliases used by different vendors and government reporting for the same or overlapping activity, alongside Aquatic Panda, Red Alpha, Red Hotel, Charcoal Typhoon, Hassium, Chromium, and TAG-22. The activity has been linked to support for Chinese intelligence and security services, including the Ministry of State Security and Ministry of Public Security, and reflects the use of ostensibly private cybersecurity firms to provide operational access, stolen data, and intrusion capabilities while preserving state plausible deniability. Operations associated with Red Scylla have targeted a broad set of victims, including U.S.-based dissidents and critics of the Chinese government, a U.S. news organization, a large U.S.-based religious organization, multiple Asian governments, and U.S. federal and state government agencies. The targeting profile indicates a primary focus on espionage, surveillance, and suppression of perceived political threats, rather than financially motivated crime or disruptive ransomware activity. The actor’s reported role within this ecosystem includes unauthorized network compromise, theft and transfer of victim data to Chinese government customers, and provision of hacking platforms for use by state security organs. Based on the available facts, Red Scylla should be understood as part of a broader China-linked contractor and proxy intrusion apparatus rather than a standalone criminal ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.