RedGolf

First seen
2014-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Financial Theft, Espionage
Profile updated
2026-07-07 11:58:30

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications healthcare-and-pharmaceutical energy-and-utilities

Context

Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group. RedGolf closely overlaps with threat activity reported in open sources under the aliases APT41/BARIUM and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward.

Detection coverage

  • 155 YARA rules

Malware & tools used

Related threat objects

Reports & references

  • justice.gov — Seven International Cyber Defendants Including Apt41 Actors Charged Connection Computer (report)
  • go.recordedfuture.com — Cta 2023 0330 (report)

External references