Red Hotel is a China-linked intrusion cluster associated with the broader Chinese government-backed cyber ecosystem and publicly tracked under multiple aliases, most notably Aquatic Panda. It has been linked to operations involving personnel from the China-based firm i-SOON and to direction or tasking by officers of China’s Ministry of Public Security. Reporting ties the group to China’s long-running "red hacker" or Honker milieu, an informal talent pool that helped seed later state-aligned advanced persistent threat activity. Red Hotel has been associated with espionage-oriented intrusions against government, media, religious, and civil-society targets, including U.S. government agencies, Asian foreign ministries, dissidents, investigative journalists, and other critics of the Chinese government. The group’s victimology and operational context are consistent with intelligence collection and domestic-security objectives rather than financially motivated crime. The cluster is known by several overlapping vendor and government tracking names, including Aquatic Panda, Red Alpha, Charcoal Typhoon, Red Scylla, Hassium, Chromium, and TAG-22. Available information indicates these names reflect partially overlapping tracking of activity connected to i-SOON and related Chinese state-linked operators rather than a clearly bounded, single independent organization. High-confidence reporting places Red Hotel within China’s contractor-enabled offensive cyber apparatus, in which ostensibly private information security firms and affiliated freelancers conduct intrusions and provide stolen data or operational support to state customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese government-backed hacking group/activity cluster connected to earlier “red hacker/Honker” communities.
Publicly tracked activity cluster associated in this PSA with i-Soon and PRC government-directed/benefiting cyber operations.
China-linked intrusion set described as tied to contract-hacker operations (i-SOON) and PRC law-enforcement tasking; targets include government, foreign ministries, dissidents, and journalists; broad global intrusion activity via contractor model.
Referenced as a Chinese government-backed activity cluster; mentioned as part of the set of modern intrusion groups whose operators are described as having roots in earlier “red hacker/Honker” communities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.