OSSTUN is a command-and-control framework associated with the China-linked threat actor RedGolf, also known as APT41. It was developed with assistance from Google Gemini, including support for C++ and Go code and code-obfuscation-related development. OSSTUN is assessed at Level 2 (“Adopting”) in the AI Malware Maturity Model, reflecting use of generative AI to augment development rather than autonomous AI-driven operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
China's APT41 leveraged Gemini for code assistance, enhancing its OSSTUN C2 framework and utilizing obfuscation libraries to increase malware sophistication.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-and-control framework mentioned as an example of a separate AI-assisted development activity; it is not the subject of the report.
C2 framework developed by APT41 (RedGolf) with LLM awareness, using Gemini in its development process.
Command-and-control (C2) framework referenced as being enhanced with Gemini-assisted code and additional obfuscation libraries to increase sophistication.
Command-and-control (C2) framework referenced as being developed/improved with assistance from Gemini prompts (per the report).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.