Raspberry Typhoon (RADIUM) is a Microsoft-tracked threat actor targeting government and telecom entities around the South China Sea.
Analyst brief
Raspberry Typhoon (RADIUM) is a threat actor tracked by Microsoft, primarily targeting nations bordering the South China Sea. It consistently goes after government ministries, military entities, and corporations tied to critical infrastructure, especially telecoms. Its main TTPs involve intelligence collection and malware execution, with persistent activity noted since January 2023. Defenders should monitor for unusual authentication attempts, suspicious malware deployments, and data exfiltration indicators, especially within government and telecommunications networks.
Raspberry Typhoon
RADIUM
unknown
Microsoft has tracked Raspberry Typhoon (RADIUM) as the primary threat group targeting nations that ring the South China Sea. Raspberry Typhoon consistently targets government ministries, military entities, and corporate entities connected to critical infrastructure, particularly telecoms. Since January 2023, Raspberry Typhoon has been particularly persistent. When targeting government ministries or infrastructure, Raspberry Typhoon typically conducts intelligence collection and malware execution. In many countries, targets vary from defense and intelligence-related ministries to economic and trade-related ministries