Redfly is a threat actor known for maintaining long-term stealthy access in an Asian electricity grid network.
Analyst brief
Redfly is a threat actor that maintained persistent access to an electricity grid organization’s network for approximately six months. It targeted a national electricity grid organization in Asia. The actor’s key TTPs likely involve persistent access mechanisms, as suspicious malware activity led to its discovery between February and August 2023. Defenders should focus on long-term stealth detection and anomaly monitoring within critical infrastructure networks.
Redfly
unknown
Redfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evidence for this attack between 28 February and 3 August 2023 after noticing suspicious malware activity within the organization’s network.
Redfly is a threat actor that targeted a national electricity grid organization in Asia. It maintained persistent access to the electricity grid organization's network for six months.
When were the indicators of compromise for Redfly discovered?+
Researchers discovered evidence for Redfly's activity between 28 February and 3 August 2023 after noticing suspicious malware activity within the network.