Operation Red Signature

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:13:55

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process. They carried this out by first stealing the company’s certificate then using it to sign the malware. They also configured the update server to only deliver malicious files if the client is located in the range of IP addresses of their target organisations.

Reports & references

  • decoded.avast.io — Avast Finds Backdoor On Us Government Commission Network (report)
  • Trend Micro — Supply Chain Attack Operation Red Signature Targets South Korean Organizations (report)

External references