A Chinese state-sponsored group known for espionage and financially motivated operations using the KEYPLUG backdoor.
Analyst brief
RedGolf is a highly likely Chinese state-sponsored espionage group closely overlapping with APT41/BARIUM, active since at least 2014. It targets a wide range of sectors including Aviation, Automotive, Education, Intergovernmental, Media and Entertainment, Information Technology, and Religious Organizations. Its primary TTP involves using the custom KEYPLUG backdoor for both Windows and Linux environments, and it is known to conduct state-sponsored espionage alongside financially motivated operations. Defenders should focus on detecting KEYPLUG network indicators and behavioral patterns, while monitoring for unusual data exfiltration across targeted sectors to identify this dual-motivated threat.
RedGolf
nation-state
Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KEYPLUG. We attribute this activity to a threat activity group tracked as RedGolf, which is highly likely to be a Chinese state-sponsored group. RedGolf closely overlaps with threat activity reported in open sources under the aliases APT41/BARIUM and has likely carried out state-sponsored espionage activity in parallel with financially motivated operations for personal gain from at least 2014 onward.