Red Nue
Also reported as LuoYu. Linked to China by two sources.
Reports per quarter
CVEs named in reports
- CVE-2016-5195 KEV
- CVE-2019-16098
- CVE-2021-20837
- CVE-2021-22555 KEV
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2022-24934
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
Malware analysis report- WinDealer (LuoYu Threat Group)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware analysis report- WinDealer (LuoYu Threat Group)
Show all 25 reports Show fewer
-
Evasive Panda APT group delivers malware via updates for popular Chinese software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evasive Panda APT group delivers malware via updates for popular Chinese software
-
Threat Thursday- China-Based APT Plays Auto-Updater Card to Deliver WinDealer Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- China-Based APT Plays Auto-Updater Card to Deliver WinDealer Malware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WinDealer dealing on the side
-
WinDealer dealing on the side _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WinDealer dealing on the side _ Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malware WinDealer used by LuoYu Attack Group - JPCERT_CC Eyes _ JPCERT Coordination Center official Blog
-
Malware WinDealer used by LuoYu Attack Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware WinDealer used by LuoYu Attack Group
Newest first. Details opens the report in Explore.