RedFoxtrot — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 9, 2026
Last Seen
January 9, 2026

RedFoxtrot is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 9, 2026; most recent activity January 9, 2026.

Overview

RedFoxtrot is a China-linked Advanced Persistent Threat (APT) group that conducts cyber-espionage operations. Recent reporting characterizes RedFoxtrot as the actor behind a campaign targeting telecommunications providers, underscoring its focus on critical infrastructure and long-term intelligence collection.

Related Threat Clusters

  • China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign

    Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…

    1 article · Updated January 9, 2026

Recent Intelligence Reports

  • Telcos subjected to China-linked cyberespionage campaign — Scworld · January 9, 2026

CVSS v3.1 Breakdown