RedFoxtrot, also known as Needleminer and Nomad Panda, is a Chinese cyber-espionage intrusion set that has been linked in open reporting to the People’s Liberation Army, including attribution to PLA Unit 69010. The group is associated with long-running intelligence collection operations and has been observed targeting telecommunications organizations and related entities in Asia, with additional indications of interest in space-sector themes and other regional targets. The actor is known for using custom malware families including Quickheal, a backdoor and credential-theft tool that has been deployed in telecom-focused campaigns. Quickheal has been observed stealing credentials from Mozilla Firefox and likely Microsoft Internet Explorer, using browser credential stores, Windows credential APIs, and encrypted communications with hardcoded command-and-control configuration. The malware demonstrates notable defense-evasion tradecraft, including VMProtect packing, custom API resolution, indirect library and function loading, and process masquerading. Campaign reporting also ties activity overlapping this cluster to persistence on victim networks, keylogging, registry-hive dumping for credential access, port scanning, proxy-aware command-and-control, and enabling remote desktop access. Operational reporting places RedFoxtrot within a broader ecosystem of China-linked espionage activity, with some campaigns showing tooling overlap alongside malware associated with other Chinese clusters. Despite using obfuscation and custom tooling, the group has also been noted for reusing infrastructure across campaigns. Its observed behavior is consistent with strategic intelligence collection against critical communications infrastructure and related sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PLA-linked intrusion set associated with the QUICKHEAL malware in campaigns targeting the telecom sector, with credential theft capabilities against Firefox and Internet Explorer and infrastructure suggesting targeting of Indian telecom and space-related entities, with possible additional targeting in the Middle East and South Korea.
China-linked espionage activity leveraging the Quickheal backdoor (32-bit DLL RasTls.dll) with VMProtect obfuscation and a custom SSL-like protocol over TCP/443 to a hardcoded C2 (swiftandfast.net), used in telecom-focused intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.