Red Juliett is a China-linked cyberespionage activity cluster associated with operations that compromise organizational networks and steal sensitive information. Its techniques overlap with Chinese government-linked activity enabled by Integrity Technology Group, a China-based contractor that develops exploitation tools, hosts infrastructure, and supports network intrusions. Red Juliett, Flax Typhoon, and Ethereal Panda are overlapping tracking labels in this context, not established interchangeable aliases; the boundaries of these clusters do not necessarily correspond directly to government attribution or to Integrity Technology Group’s operations. The associated activity targets government, critical infrastructure, manufacturing, healthcare, information technology, educational, nongovernmental, and religious organizations. Identified targets include organizations in Taiwan and the United States, as well as airports in Japan and Poland. Operations combine automated vulnerability reconnaissance, botnet infrastructure, exploitation of internet-facing services, and living-off-the-land techniques. Observed methods include password spraying against Microsoft Exchange and Microsoft 365, credential harvesting through manipulated webpages, webshell deployment, and credential extraction through DCSync. SoftEther VPN clients provide persistent remote access and conceal communications. Post-compromise collection includes databases, email, calendars, and contacts from on-premises and cloud systems, with automated mailbox collection, compression, encryption, and exfiltration. These behaviors characterize the broader Integrity Technology Group-enabled activity associated with Red Juliett and should not be interpreted as exclusive to this cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named activity cluster linked to Integrity Technology Group's contractor-enabled cyber operations. The reference associates the linked threat actors collectively with botnets, VPN infrastructure, living-off-the-land techniques and exploitation-tool repositories, but does not identify Red Juliett's individual victims or specific malware.
A named China-linked activity cluster whose campaigns are described as consistent with the disclosed Integrity Tech-enabled activity. That activity involves global network compromise and sensitive-data theft, but the article does not separately attribute individual tools or techniques to Red Juliett.
Named activity cluster materially connected through technique consistency with Integrity Tech-enabled operations. The advisory does not explicitly identify it as an alias or subgroup of another actor and does not separately assign specific malware, vulnerabilities, or targets to Red Juliett.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.