Skip to content
skopnix
← adversaries
Unknown · assessed origin China

Operation Red Signature

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of interest through the update process. They carried this out by first stealing the company’s certificate then using it to sign the malware. They also configured the update server to only deliver malicious files if the client is located in the range of IP addresses of their target organisations.

Take it with you
References
Early access

Track Operation Red Signature on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected