Red Nue (LuoYu) has targeted Chinese diaspora communities in Asia with multi-platform backdoors since at least 2017.
Analyst brief
Red Nue, also known as LuoYu, is a threat actor active since at least 2017. It primarily targets Chinese diaspora communities in Asia across Windows, macOS, and Android platforms. Its key TTPs involve multi-platform backdoors such as LootRAT (Demsty) and WinDealer, often delivered via watering hole campaigns. Defenders should focus on monitoring downloads from compromised websites and inspecting network traffic for C2 anomalies linked to these backdoors.
Red Nue
LuoYu
unknown
Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows and Macintosh (reported in open source as Demsty), as well as an Android variant known as SpyDealer. Red Nue has also used another Windows backdoor known as WinDealer since at least 2019, when it deployed it to targets as part of a watering hole campaign on a Chinese news website for the Chinese diaspora community. Parts of Asia feature heavily in Red Nue's victimology.