All actors

RedAlpha

Also reported as DeepCliff and Red Dev 3. Linked to China by one source.

Reports
8
Last reported
Known CVEs
12
Origin
China
ID
redalpha
Merge evidence
6 alias matches

Reports per quarter

  1. 2018 Q2: 1 report
  2. 2018 Q3: 3 reports
  3. 2018 Q4: no reports
  4. 2019 Q1: no reports
  5. 2019 Q2: no reports
  6. 2019 Q3: no reports
  7. 2019 Q4: no reports
  8. 2020 Q1: no reports
  9. 2020 Q2: no reports
  10. 2020 Q3: 1 report
  11. 2020 Q4: no reports
  12. 2021 Q1: no reports
  13. 2021 Q2: no reports
  14. 2021 Q3: no reports
  15. 2021 Q4: no reports
  16. 2022 Q1: no reports
  17. 2022 Q2: 1 report
  18. 2022 Q3: 1 report
  19. 2022 Q4: no reports
  20. 2023 Q1: no reports
  21. 2023 Q2: no reports
  22. 2023 Q3: no reports
  23. 2023 Q4: no reports
  24. 2024 Q1: 1 report
Dated reports, 2018 Q2 to 2024 Q1.

CVEs named in reports

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  2. Chinese Cyberespionage Originating From Tsinghua University Infrastructure

    date in the CCS '25 data Recorded Future fromORKLCCS '25 data

Newest first. Details opens the report in Explore.