RedRelay, also known as ORBWEAVER, is a covert anonymizing network and malware-associated operational infrastructure linked in reporting to multiple Chinese state-aligned intrusion sets, particularly activity tracked as APT15. It is described as a multi-hop anti-traceability system used to relay operator traffic and support clandestine cyber operations. Technical reporting associates WHIPWEAVE as a core component of the RedRelay ecosystem, and notes overlaps between RedRelay-related tooling and FCN/Free Connect as well as STN, suggesting a broader toolchain centered on covert connectivity and operational security.
RedRelay is associated with Chinese government and military customers in procurement and attribution reporting, including links to the PLA and the Ministry of Public Security, with additional claimed ties to entities associated with Haidian-based military cyber units. The tooling has been characterized as favored by Chinese state-backed operators and used in support of espionage-oriented campaigns rather than commodity cybercrime.
At high confidence from the available information, RedRelay’s primary function is to provide anonymized, covert network access and relay capability for post-compromise operations. The available facts support its role in defense evasion and post-exploitation tradecraft, but do not establish a specific initial infection vector for RedRelay itself. The strongest platform evidence points to Linux components within the ecosystem, including WHIPWEAVE-related artifacts and Linux builds of related tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Des contrats de marchés publics de l’APL confirment que Guangdong Chanming fournit un « Anonymous Network System » (identifié comme RedRelay) à une unité militaire du district de Haidian à Pékin.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Réseau covert/anonymization system fourni à une unité militaire chinoise et utilisé par APT15; WHIPWEAVE est décrit comme un composant central de ce réseau.
A security tunnel / backdoor-style tool described as being used by Chinese state-backed hackers, including 8th TRB/APT15.
A covert network tool or framework used by Chinese cyber actors, described as supporting multi-hop anonymizing traffic flow and linked in the article to Guangdong Chanming's anonymous network offerings.
RedRelay is portrayed as a covert network platform used by Chinese threat actors, apparently providing anonymous or multi-hop relay capability and linked in the article to Guangdong Chanming procurement and operational use.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.