RedLeaves, also known as BUGJUICE, is a Windows remote access trojan closely associated with China-nexus espionage activity, most notably operations attributed to APT10/MenuPass and later reporting that linked its use or overlaps to other China-aligned clusters. It has been observed since at least 2016, including in targeted email attachment campaigns, and has been used against organizations such as Japanese defense-related entities as well as victims in broader service-provider and downstream intrusion operations.
RedLeaves is widely assessed to derive substantially from the publicly available Trochilus RAT codebase. Multiple analyses have noted significant source-code overlap with Trochilus, and some reporting has also identified similarities in staging and loader logic with PlugX-associated tradecraft. The malware is typically deployed through DLL side-loading or DLL hijacking chains that use a legitimate signed executable, a malicious loader DLL, and encoded payload data. After decoding and launching, RedLeaves injects itself into another process to improve stealth.
The malware is a feature-rich backdoor that supports system and user reconnaissance, remote shell execution, file and drive operations, file upload and download, screen capture, proxying, and traffic tunneling or reverse-proxy functionality. Reported variants can collect information about logged-on users, including Remote Desktop sessions, and can dump browser-stored usernames and passwords. Command-and-control communications have been observed over TCP, HTTP, HTTPS, and custom protocols, with encrypted communications using RC4 in documented samples.
RedLeaves has figured in long-running cyber-espionage campaigns focused on information theft and persistent remote access rather than disruptive effects. Reporting has tied it to targeted intrusions against government, defense, technology, and managed service provider environments, consistent with strategic intelligence collection objectives. Later reporting also noted technical or operational overlaps between RedLeaves and activity involving other China-linked operators, though such overlaps alone are not sufficient for exclusive attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FireEye/Mandiant described HAYMAKER and SNUGRIDE as first-stage backdoors and BUGJUICE and customized QUASARRAT as second-stage backdoors during the 2016–2017 resurgence. | FBI’s FLASH explicitly presents the APT10 indicators as high-confidence and includes REDLEAVES, UPPERCUT/ANEL, and CHCHES hash artifacts.
UAT-7290 primarily leverages a Linux based malware suite but may also utilize Windows based bespoke implants such as RedLeaves ... commonly linked to China-nexus threat actors.
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA... Falcon Intelligence recently independently conducted detailed analysis of the RedLeaves malware... found it was directly sourced from Trochilus code
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
The content repeatedly notes creation of '.lnk shortcut' files in the Startup folder, such as BACKSPACE creating a shortcut in CSIDL_STARTUP, DarkGate creating an LNK object in the victim startup folder, and Operation Dream Job placing LNK files into victims' startup folder.
The executed RedLeaves launches a process (Internet Explorer) depending on its configuration, and injects itself there. Then, RedLeaves starts running in the injected process.
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
The content repeatedly notes creation of '.lnk shortcut' files in the Startup folder, such as BACKSPACE creating a shortcut in CSIDL_STARTUP, DarkGate creating an LNK object in the victim startup folder, and Operation Dream Job placing LNK files into victims' startup folder.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Priority MITRE ATT&CK Mapping ... Defense Evasion T1027.013 Encrypted/Encoded File Encoded malware strings and obfuscation
A legitimate application (EXE file): a signed, executable file which reads a DLL file located in the same folder
The executed RedLeaves launches a process (Internet Explorer) depending on its configuration, and injects itself there. Then, RedLeaves starts running in the injected process.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The data is encrypted with RC4 (the key is stored in its configuration)
Analysis of the SprySOCKS backdoor reveals some interesting findings... Meanwhile, the structure of SprySOCKS’s command-and-control (C&C) protocol is similar to one used by the RedLeaves backdoor...
The injected RedLeaves connects to command and control (C&C) servers by HTTP POST request... Destination hosts and communication methods are specified in its configuration.
Depending on the received commands, RedLeaves executes the following functions... Execute proxy function
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a malware family sharing traits with SprySOCKS.
A backdoor with significant source code overlap with SprySOCKS, built on the Trochilus codebase.
A backdoor with extensive source code overlaps with Trochilus and common traits shared with SprySOCKS.
A backdoor referenced as sharing characteristics with SprySOCKS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.