RedAlpha is a China-linked cyber espionage threat actor associated with the broader Chinese state-sponsored intrusion ecosystem and publicly linked to the contractor Anxun Information Technology Co., Ltd. (i-SOON). It is also tracked as Deepcliff and is among several clusters tied to Chinese government-directed or government-supporting cyber operations. U.S. government reporting has listed Red Alpha among the public tracking names associated with i-SOON activity, alongside aliases such as Aquatic Panda, Red Hotel, Charcoal Typhoon, Red Scylla, Hassium, Chromium, and TAG-22. RedAlpha is assessed to conduct intelligence collection and surveillance-oriented intrusions in support of Chinese state interests. Reporting connects the group to operational and organizational relationships within a wider ecosystem of private contractors, information security firms, and state customers, including the Ministry of State Security and Ministry of Public Security. This model reflects the use of shared-service providers and "digital quartermasters" that supply infrastructure, tooling, and operational support across multiple Chinese espionage teams. The actor has been linked to targeted cyber espionage against public- and private-sector organizations, including activity involving telecommunications-related data theft and infrastructure used to support persistent access and victim tracking. Recent reporting indicates that researchers identified newly observed infrastructure developments associated with RedAlpha following disclosures concerning i-SOON’s internal operations, reinforcing the assessment that the group remains active. RedAlpha should be understood as part of a broader Chinese espionage apparatus rather than an isolated criminal enterprise. Its activity aligns with long-term strategic collection, use of contractor-enabled capabilities, and overlap with other China-nexus intrusion sets operating under multiple vendor naming conventions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly tracked activity cluster associated in this PSA with i-Soon-linked intrusions and data/access sales supporting PRC intelligence and security objectives.
Chinese state-sponsored cyber group referenced in connection with operational and organizational ties to I-Soon.
A Chinese state-sponsored cyber espionage group linked to i-SOON, involved in espionage operations and continuing infrastructure development after the leak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.