Home/Threat Actor/RedHotel
Threat Actor

RedHotel

redhotel · china · active since 2019

RedHotel is a China-aligned cyber-espionage cluster active since 2019 and publicly consolidated by Recorded Future Insikt Group's seminal August 2023 disclosure as a prolific Chinese state- sponsored actor operating at a global scale, distinct from but operationally adjacent to the Earth Lusca / Aquatic Panda / Charcoal Typhoon cluster, with documented operations across 17 countries spanning Asia, Europe, and North America against government, religious-organization (Tibetan, Catholic, Falun Gong, Uyghur diaspora), academic, media, telecommunications, technology, and notably the hospitality industry (the source of the cluster's name and a signature differentiator from adjacent China-aligned clusters), using a Winnti-ecosystem toolkit anchored on Cobalt Strike, ShadowPad, PlugX, FunnySwitch, BadIIS web shells, and shared MSS-adjacent infrastructure.

china confidence: high 7 aliases

Profile

RedHotel is a China-aligned cyber-espionage cluster active since at least mid-2019 and publicly disclosed in consolidated form by Recorded Future Insikt Group in August 2023 ("RedHotel, A Prolific, Chinese State-Sponsored Group Operating at a Global Scale"). The cluster is widely assessed by Recorded Future, Mandiant, Microsoft, Trend Micro, and other vendor research teams to operate in alignment with Chinese state interests, likely with MSS (Ministry of State Security) tasking, and operationally adjacent to the broader Winnti / APT41 / Earth Lusca ecosystem of China-aligned actors. No formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published; the "MSS-aligned" framing rests on vendor research and is suspected rather than formally confirmed. RedHotel is treated as a distinct operational cluster rather than an alias for Earth Lusca (already covered in earth_lusca.yaml). Recorded Future's seminal August 2023 disclosure was explicit that RedHotel shares tooling (Cobalt Strike, ShadowPad, FunnySwitch, BadIIS, PlugX) and ecosystem affiliation with these adjacent clusters but operates a distinct victimology, infrastructure, and operational tempo. Early pre-2023 reporting frequently conflated RedHotel activity with the broader Aquatic Panda / Earth Lusca / TAG-22 / Charcoal Typhoon activity stream.

the Recorded Future August 2023 consolidation established the distinct cluster identity. A defining feature of RedHotel, and the source of the cluster's Recorded-Future-assigned name, is sustained targeting of the hospitality industry alongside the more conventional government and religious-organization espionage portfolio. Hotels and resorts in Hong Kong, Macau, Southeast Asia, and Europe provide rich collection environments for travel-pattern collection against business and diplomatic travelers passing through these high- throughput regional hubs.

hospitality-industry IT environments are often comparatively less hardened than government environments. The hospitality-targeting signature differentiates RedHotel from the otherwise-similar Earth Lusca operational profile and from the older DarkHotel cluster (South-Korea-aligned, separately tracked, comparable hospitality-targeting tradecraft but operationally and attribution-wise distinct). Recorded Future's August 2023 disclosure documented operations against organizations in 17 countries spanning Asia (Hong Kong, Macau, Taiwan, Vietnam, Mongolia, Tibet, India, Indonesia, Malaysia, Pakistan, Philippines, Thailand), Europe (Italy, Belgium, Germany), and North America (United States) from 2019 through 2023. Victim categories include government, religious organizations (Tibetan, Catholic, Falun Gong, Uyghur diaspora), academic, media, telecommunications, technology, manufacturing, and the hospitality industry. The substantial overlap of religious-organization and Tibetan-diaspora victim categories between RedHotel and Earth Lusca is one source of the early conflation of the two clusters and remains the strongest signal of both clusters operating within a shared MSS-adjacent ecosystem. Operationally RedHotel operates a comparatively standard China- aligned toolkit with extensive Winnti-ecosystem tooling overlap. Core implants include ShadowPad (the modular Winnti-shared implant), PlugX / Korplug, FunnySwitch backdoor, and Winnti malware family components, with heavy reliance on Cobalt Strike Beacon for hands-on-keyboard operations. BadIIS web-shell deployment for long-dwell persistence in compromised IIS-hosted web environments, with SEO-fraud and traffic-redirection components, has been observed in RedHotel-adjacent activity though the financial-motivation component is less prominent in RedHotel-specific reporting than in Earth Lusca reporting. A handful of operational notes: First, the cluster is operationally distinct from the older DarkHotel cluster (South-Korea-aligned, Kaspersky 2014 disclosure, heavy hotel-WiFi-targeting against business travelers). The naming similarity is coincidental.

the two clusters are not related operationally or by attribution. Second, the cluster is operationally adjacent to but distinct from Earth Lusca / Aquatic Panda / Charcoal Typhoon (already covered as earth_lusca.yaml in this corpus). The two clusters share tooling and ecosystem affiliation but operate distinct victimologies, infrastructure, and tempo. Pre-2023 reporting that conflates the two should be re-read with the Recorded Future August 2023 consolidation in mind. Third, attribution to MSS specifically, though dominant in vendor reporting, has not been confirmed by formal state attribution and should be presented as suspected.

Aliases

7
redhotelred hotelred_hotelaquatic panda overlapcharcoal typhoon overlapearth lusca overlapchromium overlap

Notable Campaigns

8
2024-2025Continued Operations (2024-2025)
2023Recorded Future: RedHotel, A Prolific, Chinese State-Sponsored Group Operating at a Global Scale (August 17, 2023)
2022-2025BadIIS Web-Shell and SEO-Fraud Adjacency (2022-2025)
2022-2024European Government and Hospitality Targeting Subset (2022-2024)
2021-2024Macau and Hong Kong Hospitality / Gambling Targeting (2021-2024)
2020-2024Religious-Organization and Dissident Targeting (2020-2024)
2019-2024Hospitality and Hotel Industry Targeting Signature (2019-2024)
2019-2022Pre-Disclosure Activity (2019-2022)

Attribution & Reporting

Attributed by
Recorded Future Insikt GroupMandiantMicrosoftTrend MicroCrowdStrikeSentinelOneCluster25CyfirmaCisco TalosKasperskyVolexitySymantecESETGroup-IBSophos
Key reporting
reportRecorded Future Insikt Group: RedHotel, A Prolific, Chinese State-Sponsored Group Operating at a Global Scale (August 17, 2023), seminal cluster naming and 17-country victimology
reportRecorded Future Insikt Group: TAG-22 Tracking (prior to RedHotel and Earth Lusca consolidation, 2021)
reportMandiant: China-Linked Cluster Tracking (multiple, RedHotel adjacency)
reportMicrosoft: Threat Actor Naming Taxonomy (April 2023), Charcoal Typhoon framework
reportTrend Micro: Delving Deep, An Analysis of Earth Lusca's Operations (January 2022), adjacent cluster
reportSentinelOne Labs: BadIIS China-Link (2024), ecosystem tooling
reportCluster25: RedHotel China Cluster Operational Profile
reportCyfirma: RedHotel China State-Sponsored Tracking (2023-2024)
reportCrowdStrike: Aquatic Panda Log4j Exploitation (December 2021), adjacent cluster
reportSekoia: Active China-Aligned Clusters Tracking (multiple, 2023-2024)
reportMalpedia Actor Profile: RedHotel

Operational

State sponsor

Suspected China-aligned advanced persistent threat group, widely assessed by vendor research (Recorded Future Insikt Group's seminal August 2023 disclosure, Mandiant, Microsoft, Trend Micro, and others) to operate in alignment with Chinese state interests , likely with MSS (Ministry of State Security) tasking, and operationally adjacent to the broader Winnti / APT41 / Earth Lusca ecosystem of China-aligned dual-motivation actors. RedHotel is treated as a distinct operational cluster rather than as an alias for Earth Lusca / Aquatic Panda / Charcoal Typhoon, Recorded Future's seminal disclosure was explicit that RedHotel shares tooling (Cobalt Strike, ShadowPad, BadIIS, PlugX) and ecosystem affiliation with these adjacent clusters but operates a distinct victimology, infrastructure, and operational tempo. No formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published.

the "MSS-aligned" framing rests on vendor research and should be treated as suspected rather than formally confirmed.

Motivations
espionage, intelligence_gathering, geopolitical_collection, dissident_surveillance, religious_organization_surveillance, economic_intelligence, hospitality_industry_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTA
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin