Red Foxtrot
Red Foxtrot is a China-linked threat actor cluster publicly reported by Recorded Future and linked in a 2021 report to the Chinese People’s Liberation Army (PLA) Unit 69010. In the provided reporting, Cisco Talos states that UAT-7290 shares significant overlap with Red Foxtrot in victimology, infrastructure, and tooling, and that victimology and infrastructure also overlap with Red Foxtrot. The surrounding activity is described as espionage-focused intrusions against critical infrastructure, primarily telecommunications providers in South Asia, with more recent expansion into Southeastern Europe. Observed tactics and tooling in the overlapping activity include extensive pre-intrusion reconnaissance, exploitation of one-day vulnerabilities in public-facing edge networking devices, target-specific SSH brute force, use of Linux-focused malware including RushDrop, DriveSwitch, SilentRaid, and Bulbature, and establishment of Operational Relay Box infrastructure. Based on the provided content, Red Foxtrot is associated with China/PLA-linked espionage activity; however, the detailed TTPs and malware above are described in the context of overlap with UAT-7290 rather than being directly and independently attributed to Red Foxtrot in the source material. Known alias in the provided content: red_foxtrot.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked threat actor publicly linked by Recorded Future to PLA Unit 69010 and noted here for overlap in victimology, infrastructure, and tooling with UAT-7290.
China-linked threat actor referenced because UAT-7290 shares overlap in victimology, infrastructure, and tooling with it; publicly linked to PLA Unit 69010.
Referenced as a China-linked threat actor whose victimology and infrastructure overlap with UAT-7290.
China-linked threat group referenced due to overlap with UAT-7290 in victimology, infrastructure, and tooling; publicly linked by Recorded Future to PLA Unit 69010.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.