Operation Redkanku is a China-linked espionage activity cluster identified as one of several distinct users of the ShadowPad malware platform since 2017. It is tracked as a separate cluster alongside other ShadowPad-using groups such as APT41, Tick & Tonto Team, Operation Redbonus, and Fishmonger. The cluster’s inclusion in this set indicates operational use of ShadowPad, a privately sold modular backdoor and successor to PlugX that has featured prominently in long-running espionage operations. Operation Redkanku is associated with the ShadowPad ecosystem rather than with publicly documented ransomware activity. ShadowPad is a modular shellcode-based backdoor that loads a root component and additional plugins in memory, supports remote plugin delivery, and is designed for stealthy long-term access. Across ShadowPad-linked operations, the platform has been observed with anti-detection improvements, persistence functionality, and flexible command-and-control support. Because ShadowPad is used by multiple China-linked intrusion clusters, attribution of individual campaigns requires corroborating evidence beyond malware overlap alone. Available high-confidence information supports classifying Operation Redkanku as an espionage-oriented threat cluster, but does not provide sufficiently specific public detail here on its victim geography, sector focus, sub-groups, or unique tradecraft beyond its use of ShadowPad.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster identified as using ShadowPad since 2017.
Named as one of the activity clusters identified as a ShadowPad user.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.