RedRelay, also referred to as ORBWEAVER, is a covert anonymizing network and malware-enabled relay infrastructure associated with Chinese state-linked cyber operations. It is described as being used by multiple Chinese threat actors and is closely associated with WHIPWEAVE, a core malware component used to build or operate the relay network. Reporting has linked RedRelay and related tooling to infrastructure and development overlaps involving Guangdong Chanming and the Free Connect (FCN) or STN toolset, suggesting a relationship between commercialized anonymization software and operational cyber infrastructure.
Functionally, RedRelay appears designed to provide anti-traceability and multi-hop traffic forwarding for offensive operations, enabling operators to conceal origin infrastructure and route malicious traffic through covert relay nodes. The associated WHIPWEAVE component has been characterized as central to this relay architecture, particularly in Linux environments. The broader ecosystem has been tied to Chinese espionage activity and assessed as supporting operations attributed to clusters tracked as APT15, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon, and related aliases.
Available information supports viewing RedRelay primarily as covert relay and anonymization malware infrastructure used in support of post-compromise operations and defense evasion rather than as a conventional initial-access payload. It has been discussed in connection with Chinese military and security customers, including entities linked to the PLA and Ministry of Public Security, though some attribution details remain allegations rather than independently established fact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WHIPWEAVE is a core component of the RedRelay covert network (also known as ORBWEAVER), a tool used by several known Chinese cyber actors.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
it outlines the infrastructure layer behind cyber campaigns, including software that may help operators hide command traffic, relay data, and reduce the chance that victims can trace activity back to its source.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A security tunnel / backdoor-style tool described as being used by Chinese state-backed hackers, including 8th TRB/APT15.
A covert network tool or framework used by Chinese cyber actors, described as supporting multi-hop anonymizing traffic flow and linked in the article to Guangdong Chanming's anonymous network offerings.
RedRelay is portrayed as a covert network platform used by Chinese threat actors, apparently providing anonymous or multi-hop relay capability and linked in the article to Guangdong Chanming procurement and operational use.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.