Home/Threat Actor/RedFoxtrot
Threat Actor

RedFoxtrot

redfoxtrot · china · active since 2014

RedFoxtrot (TAG-28) is a China-aligned cyber-espionage cluster active since 2014, publicly disclosed and attributed by Recorded Future's Insikt Group in June 2021 to PLA Unit 69010, a Western Theater Command Technical Reconnaissance Bureau headquartered in Urumqi, following operational-security failures by a cluster operator whose personal Chinese-platform social-media activity was tied to cluster malware-development infrastructure, and responsible for sustained operations against Indian aerospace and defense (including during the 2020-2021 China-India border tensions), Afghan, Pakistani, Kyrgyz, Tajik, Kazakh, Mongolian, Nepalese, and Bhutanese government and telecommunications targets using PlugX, ShadowPad, IceFog, PCShare RAT, Royal Road RTF weaponizer, and Cobalt Strike toolkits shared across the broader Chinese-state-aligned ecosystem.

china confidence: high 11 aliases

Profile

RedFoxtrot (also tracked as TAG-28 by Recorded Future prior to the June 2021 disclosure consolidation, and known by its assessed sponsor as PLA Unit 69010) is a China-aligned cyber-espionage cluster active since at least 2014, publicly disclosed and named by Recorded Future's Insikt Group in June 2021 in a report titled "Threat Activity Group RedFoxtrot Linked to China's PLA Unit 69010 Following Targeted Intrusions Across Central, South Asia." The cluster is widely assessed to operate on behalf of PLA Unit 69010, reported by Recorded Future to be a Western Theater Command Technical Reconnaissance Bureau headquartered in Urumqi, Xinjiang Uyghur Autonomous Region. The PLA Unit 69010 attribution rests on operational-security failures by one cluster operator (codename "Vendor") whose personal social-media activity on Weibo, QQ, and other Chinese-platform sources, including photographs identifying themselves as a Unit 69010 officer in uniform, was tied to the cluster's malware- development infrastructure through certificate, infrastructure, and timing analysis. The case is widely cited in attribution- methodology literature as a rare and important example of operator-level OPSEC failure producing concrete state-attribution at the PLA-unit level, comparable in methodological significance to the 2013 Mandiant APT1 / PLA Unit 61398 attribution. No formal state attribution by the US, UK, EU, or any other government has been issued.

the attribution rests on Recorded Future's open- source analysis but is widely accepted across vendor research. Targeting focus is overwhelmingly directed at South and Central Asian government, defense, telecommunications, and aerospace entities, consistent with Unit 69010's assessed mission profile for Western Theater Command technical reconnaissance. Victim countries include India (heavily, with continued operations during the China-India border tensions of 2020-2021 including the Galwan Valley incident and subsequent Ladakh and Arunachal Pradesh standoffs), Afghanistan, Pakistan, Kyrgyzstan, Tajikistan, Kazakhstan, Mongolia, Nepal, and Bhutan. Documented Indian defense-industrial-base targets include Bharat Dynamics Limited and Hindustan Aeronautics Limited adjacency.

Central Asian telecommunications providers in Kyrgyzstan, Tajikistan, and Kazakhstan.

and broader regional government and diplomatic entities. Operationally RedFoxtrot operates a comparatively standard Chinese-aligned toolkit shared across the broader PLA / MSS tooling ecosystem. Core implants include PlugX (Korplug), ShadowPad, IceFog, PCShare RAT, and Poison Ivy, with substantial reliance on Cobalt Strike for hands-on-keyboard operations. The cluster has been a heavy user of the Royal Road RTF weaponizer ("8.t document weaponizer," originally documented by Anomali), a shared tool across multiple Chinese-aligned clusters that generates weaponized RTF documents exploiting CVE-2017-11882 and related Equation Editor vulnerabilities. The shared-tooling pattern complicates attribution at the malware-family level but cluster-level operational signatures (infrastructure, victimology, operator workflow) remain distinguishable. A handful of operational notes: First, RedFoxtrot is operationally distinct from APT10 (MSS Tianjin Bureau, already covered as apt10_stonepanda), APT41 (MSS / Chengdu 404, already covered), and APT31 (MSS Hubei / Wuhan XRZ, already covered) despite tooling-overlap and similar Chinese-aligned operational style. PLA Unit 69010 attribution places RedFoxtrot in the PLA SSF (Strategic Support Force) ecosystem rather than in MSS, the only other PLA-attributed cluster in this corpus is APT1 (PLA Unit 61398) and Naikon (PLA Unit 78020). Second, the cluster's name "RedFoxtrot" was chosen by Recorded Future as a consolidation of prior TAG-28 tracking.

some earlier reporting and infrastructure references may use TAG-28 or generic "China-aligned" naming for activity that retrospectively maps to RedFoxtrot. Third, attribution to PLA Unit 69010 specifically, though widely accepted, rests on open-source analysis by a single research team and has not been confirmed by formal state attribution. The "PLA Unit 69010" framing should be treated as suspected rather than formally confirmed.

Aliases

11
redfoxtrotred foxtrotred_foxtrotfoxtrottag-28tag_28threat activity group 28pla unit 69010mua 69010western theater command trbaxiomaticasymptote overlap

Notable Campaigns

8
2023-2025Continued Operations Across South and Central Asia (2023-2025)
2022Bhutanese and Nepalese Government Targeting (2022)
2021-2023Central Asian Telecom Targeting (2021-2023)
2021Recorded Future: RedFoxtrot Linked to China's PLA Unit 69010 (June 16, 2021)
2021OPSEC-Failure Attribution Lesson (Analytic Note, 2021)
2020-2022Sustained Indian Defense Industrial Base Targeting (2020-2022)
2018-2024Royal Road RTF Weaponizer Lineage and Ecosystem Sharing (2018-2024)
2014-2020Pre-Disclosure Activity (2014-2020)

Attribution & Reporting

Attributed by
Recorded Future Insikt GroupMandiantMicrosoftCrowdStrikeCisco TalosTrend MicroKasperskySymantecESETSophosCluster25CyfirmaSentinelOneQiAnXin RedDripVolexity
Key reporting
reportRecorded Future Insikt Group: Threat Activity Group RedFoxtrot Linked to China's PLA Unit 69010 Following Targeted Intrusions Across Central, South Asia (June 16, 2021), seminal cluster naming and attribution
reportRecorded Future Insikt Group: TAG-28 Tracking (prior to RedFoxtrot consolidation, 2020-2021)
reportMandiant: China Cyber Operations Tracking (multiple years, RedFoxtrot adjacency)
reportCrowdStrike: 2022 Falcon OverWatch, ShadowPad Sharing Across Chinese Clusters
reportCluster25: RedFoxtrot PLA Unit 69010 Operational Profile (2022-2023)
reportCyfirma: RedFoxtrot China PLA Unit 69010 (2022-2023)
reportSentinelOne Labs: Aoqin Dragon and Related Chinese-Linked APT Tracking (RedFoxtrot adjacency)
reportAnomali: Royal Road RTF Weaponizer Re-Dive (Chinese-cluster shared tooling)
reportESET: Winnti Group Targets Hong Kong Universities (Royal Road ecosystem reference)
reportMalpedia Actor Profile: RedFoxtrot
reportQiAnXin RedDrip: PLA-Adjacent China-Aligned Cluster Tracking (Chinese-language, multiple)

Operational

State sponsor

Suspected to operate on behalf of the People's Liberation Army Strategic Support Force (PLA SSF), specifically PLA Unit 69010, reported by Recorded Future's Insikt Group in June 2021 to be a Western Theater Command Technical Reconnaissance Bureau headquartered in Urumqi, Xinjiang Uyghur Autonomous Region. The attribution rests on operational-security failures by one cluster operator (codename "Vendor") whose personal social-media activity on Weibo, QQ, and other Chinese platforms, including photographs identifying themselves as a PLA Unit 69010 officer in uniform, was tied to the cluster's malware-development infrastructure through certificate, infrastructure, and timing analysis. Unit 69010's mission is consistent with the cluster's victimology (South Asian, Central Asian, and adjacent regional targets of Western Theater Command interest). No formal state attribution by the US, UK, EU, or any other government has been issued.

the "PLA Unit 69010" framing rests on Recorded Future's open-source analysis and is widely accepted across vendor research, but should be treated as suspected rather than formally confirmed.

Motivations
espionage, intelligence_gathering, military_intelligence, geopolitical_collection, defense_industrial_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTA
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin