RedGolf
- First seen
- 2014-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Financial Theft, Espionage
- Profile updated
- 2026-07-07 11:58:30
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications healthcare-and-pharmaceutical energy-and-utilities
Context
Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group. RedGolf closely overlaps with threat activity reported in open sources under the aliases APT41/BARIUM and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward.
Detection coverage
- 155 YARA rules
Malware & tools used
- PlugX (malware)
- Cobalt Strike (malware)
- APT41 (threat-actor)
- KEYPLUG (malware)
Related threat objects
- APT41 (threat-actor)
Reports & references
- justice.gov — Seven International Cyber Defendants Including Apt41 Actors Charged Connection Computer (report)
- go.recordedfuture.com — Cta 2023 0330 (report)