Redfly is a China-linked espionage threat actor associated with the broader APT41 nexus and referenced alongside related clusters such as Blackfly and Grayfly. The group has been connected to use of ShadowPad, a modular remote access Trojan widely used by multiple China-aligned intrusion sets, and has appeared in reporting on campaigns targeting critical infrastructure and other strategically significant organizations. Tradecraft associated with Redfly and adjacent APT41-nexus activity includes exploitation of internet-facing systems for initial access, stealthy persistence, DLL sideloading, in-memory loading of malware components, process injection, credential theft, and post-compromise use of modular backdoors. Tooling observed in overlapping China-linked operations includes ShadowPad and other loaders and backdoors used to establish durable access, execute arbitrary commands, transfer files, gather victim information, and support lateral movement and privilege escalation. Operational patterns are consistent with long-term intelligence collection rather than disruptive or financially motivated activity. Redfly should be understood as part of the ecosystem of Chinese state-aligned espionage operations that reuse shared malware families, loaders, and intrusion techniques across partially overlapping clusters. Public reporting commonly places it within the APT41-related landscape rather than as a standalone criminal enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT41-nexus group referenced as associated with ShadowPad usage.
Mentioned only as a cited reference title in the timeline/source list.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.