Operation Redbonus is a China-linked espionage activity cluster identified as one of several distinct users of the ShadowPad malware platform since 2017. It is tracked as a separate cluster alongside APT41, Tick & Tonto Team, Operation Redkanku, and Fishmonger, reflecting the broader ecosystem of operators using the privately sold ShadowPad backdoor. Operation Redbonus is associated with the use of ShadowPad, a modular backdoor and malware platform that emerged around 2015 as a successor to PlugX. ShadowPad is notable for its plugin-based architecture, in-memory loading of components, remote extensibility, and continued evolution with stronger anti-detection and persistence features. Its design supports staged loading through an obfuscated shellcode loader and a root component that decrypts and loads additional plugins, enabling flexible post-compromise capability expansion. Because ShadowPad is a commercially supplied platform rather than an openly shared framework, attribution of Operation Redbonus should be treated cautiously. Shared access to ShadowPad among multiple China-linked espionage clusters complicates efforts to distinguish operators based on malware alone. High-confidence assessment of Operation Redbonus therefore rests primarily on its identification as a distinct ShadowPad-using cluster within that broader ecosystem, rather than on uniquely documented victimology or tradecraft beyond ShadowPad use. Operation Redbonus is best understood as part of the wider landscape of China-linked intrusion activity that benefits from shared or privately sold malware tooling to reduce development costs and accelerate espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster identified as using ShadowPad since 2017.
Named as one of the activity clusters identified as a ShadowPad user.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.