Operation Redbonus is a cyberespionage activity cluster tracked by SentinelOne and first observed using ShadowPad in late 2019. Its malware arsenal also includes Whitebird, IceFog, and customized PCShare backdoors. The cluster has demonstrated interest in Indian targets through dynamic DNS infrastructure impersonating Indian institutions. ShadowPad provides a modular backdoor architecture with runtime plugin loading and multiple command-and-control protocols. Operation Redbonus is tracked separately from other ShadowPad-using clusters, including APT41, Tick/Tonto Team, Operation Redkanku, and Fishmonger; shared use of this malware does not establish that these clusters represent the same actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster identified as using ShadowPad since 2017.
Named as one of the activity clusters identified as a ShadowPad user.
An unattributed ShadowPad activity cluster first observed in late 2019. It also used Whitebird, IceFog, and customized PCShare, and showed interest in Indian targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.