RedAlpha is a China-linked cyber espionage threat actor associated with the broader Chinese state-sponsored intrusion ecosystem. It has been linked to the contractor Anxun Information Technology Co., Ltd. (i-SOON), with reporting indicating operational and organizational ties between RedAlpha, other Chinese espionage groups such as RedHotel and POISON CARP, and Chinese government customers. U.S. government reporting has also mapped i-SOON activity to multiple public tracking names including Red Alpha, indicating overlap between contractor-supported operations and publicly tracked intrusion clusters. RedAlpha is assessed to conduct espionage-focused operations against public- and private-sector targets. Reporting tied to the i-SOON leak indicates involvement in campaigns supported by shared-service providers or "digital quartermasters" within China’s offensive cyber ecosystem, suggesting access to pooled infrastructure, tooling, and operational support rather than purely standalone tradecraft. Newly observed domain and infrastructure developments linked to RedAlpha after the i-SOON leak further support that the cluster remains operational. High-confidence reporting in the available material does not provide a distinct, actor-specific malware repertoire, victim-country list, or sector list unique to RedAlpha beyond its placement in the Chinese state-sponsored espionage ecosystem and its ties to i-SOON. Known related groups and aliases appearing in the available reporting include Deepcliff and Red Alpha.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly tracked activity cluster associated in this PSA with i-Soon-linked intrusions and data/access sales supporting PRC intelligence and security objectives.
Chinese state-sponsored cyber group referenced in connection with operational and organizational ties to I-Soon.
A Chinese state-sponsored cyber espionage group linked to i-SOON, involved in espionage operations and continuing infrastructure development after the leak.
Mentioned as a past user of njRAT for information theft and espionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.