RedTeam is a threat actor observed advertising a brute-force tool named Brutus that is designed to target Fortinet services. The actor’s publicly described tradecraft centers on credential attacks against exposed remote access infrastructure. Brutus has been described as supporting attacks against SSH, RDP, VNC, and shell-based remote access services, with integrated scanning to identify exposed targets, proxy support to help obfuscate attack traffic, and dynamic credential generation to expand password-guessing attempts. These characteristics indicate an operational focus on reconnaissance, scanning, brute-force activity, and credential-based initial access, with supporting defense-evasion features. Available information directly links RedTeam to the development or sale of offensive tooling for credential attacks, but does not provide high-confidence attribution to a nation-state, a specific country of origin, or a broader campaign history beyond this activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.