RedFoxtrot is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 9, 2026; most recent activity January 9, 2026.
RedFoxtrot is a China-linked Advanced Persistent Threat (APT) group that conducts cyber-espionage operations. Recent reporting characterizes RedFoxtrot as the actor behind a campaign targeting telecommunications providers, underscoring its focus on critical infrastructure and long-term intelligence collection.
Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…