WHIPWEAVE is a malware component associated with the RedRelay covert network, also tracked as ORBWEAVER. It has been linked to anonymizing and relay infrastructure used to conceal command traffic and route communications through multi-hop operational relay boxes. Available reporting ties WHIPWEAVE to technical overlaps with FCN (Free Connect) and STN Security Tunnel tooling, including shared Linux build characteristics, suggesting a close development relationship among these tools.
WHIPWEAVE is described as a core element of RedRelay/ORBWEAVER infrastructure rather than a commodity malware family. Its observed role is consistent with covert tunneling, proxying, and post-compromise communications support for espionage operations. The malware has been associated with Linux artifacts, and the surrounding toolchain indicates use in anti-traceability and relay-based network operations.
Use of RedRelay/ORBWEAVER has been linked in public reporting to multiple Chinese cyber espionage clusters, especially APT15 and its commonly cited aliases including Ke3chang, Vixen Panda, Playful Dragon, Red Vulture, and Nylon Typhoon. Some reporting further associates the broader infrastructure ecosystem with Chinese state customers and military-linked entities, though those attribution claims should be treated cautiously where independently uncorroborated.
High-confidence evidence supports characterizing WHIPWEAVE as a covert networking backdoor or tunneling component used in support of espionage, with emphasis on stealthy relay communications and operational concealment rather than destructive or financially motivated activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Une commande Linux hautement spécifique présente dans les builds FCN : correspond exactement à celle trouvée dans bulbature, connu sous le nom de WHIPWEAVE — composant central du réseau covert RedRelay (alias ORBWEAVER), utilisé par plusieurs acteurs cyber chinois.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Composant central d’un réseau covert nommé RedRelay/ORBWEAVER, lié ici à l’infrastructure clandestine utilisée par des acteurs cyber chinois.
WHIPWEAVE is described as malware associated with the RedRelay/ORBWEAVER covert network and appears tied to relay/tunneling infrastructure used to conceal command traffic and support long-term espionage operations.
A malware/toolset associated with a covert relay network used to conceal command traffic and route activity through multiple systems, complicating attribution and investigation.
A malware component used within the RedRelay/ORBWEAVER covert network, apparently providing anonymizing or multi-hop traffic capabilities aligned with anti-traceability network operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.