RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-24682 | Cross-Site Scripting in Synacor Zimbra Collaboration Suite Calendar Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (CWE-79) flaw with improper encoding/escaping (CWE-116) in its Calendar feature, allowing an attacker to execute arbitrary code. The flaw is triggered through the Calendar functionality, where attacker-supplied content is rendered without proper encoding, enabling script/code execution in the context of affected ZCS deployments. A successful attacker can execute arbitrary code in the targeted environment, and CISA notes known ransomware use in the wild. Organizations running Synacor ZCS are affected; the specific affected version ranges are not stated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-25 with a 30.9% EPSS probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply updates per vendor instructions, as required by the CISA KEV listing. Because ransomware use is known, prioritize patching internet-facing ZCS servers, review Zimbra mailbox/Calendar logs for signs of malicious items or unauthorized access, and confirm users' sessions and accounts have not been compromised. Until patched, treat untrusted calendar invites as untrusted input and limit exposure of the ZCS web interface. | 6.1 | 31% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Zimbra servers (public scans have shown roughly 50,000+ ZCS instances online) | |
| CVE-2022-27924 +1 in the same advisory: …27925 | Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile). Do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering. | 7.5 group max | 85% | KEV ransomware |
| mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions | |
| CVE-2022-30333 | Directory Traversal in RARLAB UnRAR (Linux/UNIX) Enables Arbitrary File Writes RARLAB's UnRAR command-line decompression tool on Linux and UNIX, in versions before 6.12, contains a directory traversal flaw (CWE-22, with symlink-based path confusion per CWE-59) that lets a crafted RAR archive write files to arbitrary filesystem locations during an extract/unpack operation. It is triggered whenever an application passes an attacker-supplied archive to unrar, most prominently Zimbra Collaboration Suite, which unpacked RAR attachments from incoming email, enabling pre-authentication attacks against webmail tracked separately as CVE-2022-41352. By planting files at chosen paths — for example writing an SSH key to ~/.ssh/authorized_keys or dropping a web shell under a web root — an attacker can escalate an arbitrary file write into code execution on the server, requiring no privileges or user interaction per the CVSS vector. Only the Linux/UNIX UnRAR utility is affected; WinRAR and RAR for Android are not. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-09 with known ransomware use, public PoCs exist, and EPSS estimates a ~99% probability of exploitation within 30 days. Do: Upgrade UnRAR to 6.12 or later on all Linux and UNIX systems and apply Debian's patched unrar package; Zimbra administrators should apply Zimbra's released security patches, which ship the fixed UnRAR. As an interim mitigation, restrict or monitor services that automatically extract RAR archives from untrusted sources, and hunt for indicators such as unexpected ~/.ssh/authorized_keys entries, planted symlinks, or web shells under web roots. Because the flaw is on CISA's KEV list with known ransomware use, treat patching as time-critical. | 7.5 | 99% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed servers (dominated by Zimbra mail servers that auto-extract RAR attachments), with the total UnRAR installed base on… | |
| CVE-2022-37042 | Unauthenticated ZIP Path Traversal RCE in Synacor Zimbra Collaboration Suite CVE-2022-37042 is an authentication bypass combined with a ZIP archive path traversal (CWE-22) in the mboximport functionality of Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0, and it exists because of an incomplete fix for CVE-2022-27925. An attacker does not need a valid authtoken: by sending an attacker-crafted ZIP archive to the mboximport endpoint, the flaw lets arbitrary files be extracted and written outside the intended directory. Successful file-write primitives on a Zimbra server lead directly to remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). All internet-reachable ZCS 8.8.15 and 9.0 deployments are in scope, and the flaw has been added to CISA KEV (2022-08-11) with known ransomware use and a 91.9% EPSS exploitation probability. Exploitation is confirmed in the wild at scale: CISA ordered civilian agencies to patch after mass exploitation, and headlines attribute campaigns to both North Korean (No Pineapple) and Chinese state-sponsored (RedHotel) actors. Do: Immediately apply the current ZCS 8.8.15 and 9.0 patch releases per Synacor/Zimbra vendor instructions, as required by CISA's KEV required action. Until patched, restrict or block unauthenticated access to the mboximport/service extension endpoint (e.g., via firewall or reverse proxy rules) and verify no authtoken-less requests have reached it. Hunt for unexpected files written by the mailbox process, review mailboxd/access logs for ZIP uploads lacking an authtoken, and check for follow-on webshell, lateral-movement, or ransomware artifacts given confirmed ransomware use. | 9.8 | 92% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Zimbra servers (public internet-wide scans show on the order of 10k-100k ZCS instances) |
Full article1,066 words · extracted from recordedfuture.com · click to collapse
New Insikt Group research examines RedHotel, a Chinese state-sponsored threat activity group that stands out due to its persistence, operational intensity, and global reach. RedHotel's operations span 17 countries in Asia, Europe, and North America from 2021 to 2023. Its targets encompass academia, aerospace, government, media, telecommunications, and research sectors. Particularly focused on Southeast Asia's governments and private companies in specified sectors, RedHotel's infrastructure for malware command-and-control, reconnaissance, and exploitation points to administration in Chengdu, China. Its methods align with other contractor groups linked to China's Ministry of State Security (MSS), indicating a nexus of cyber talent and operations in Chengdu.
Schematic of RedHotel’s multi-tiered C2 infrastructure network
Since at least 2019, RedHotel has exemplified a relentless scope and scale of wider PRC state-sponsored cyber-espionage activity by maintaining a high operational tempo and targeting public and private sector organizations globally. The group has dual missions of intelligence gathering and economic espionage. It targets both government entities for traditional intelligence and organizations involved in COVID-19 research and technology R&D. Notably, it compromised a US state legislature in 2022, highlighting its expanded reach. The majority of observed victim organizations were government organizations, including prime ministers’ offices, finance ministries, legislative bodies, and interior ministries, aligning with the group’s likely espionage tasking. However, on some occasions, such as the group’s targeting of the Industrial Technology Research Institute (ITRI) in Taiwan, reported in July 2021, or of COVID-19 research, the likely motivation was industrial and economic espionage. The group’s historical targeting of the online gambling industry catering to the Chinese market is also indicative of wider trends across China-based cyber-espionage actors observed by Insikt Group, and is likely in part intended to gather intelligence in support of wider crackdowns on online gambling by the Chinese government.
RedHotel Tech Stack
RedHotel employs a multi-tiered infrastructure with a distinct focus on reconnaissance and long-term network access via command-and-control servers. The group’s multi-tier infrastructure setup consists of large quantities of provisioned virtual private servers (VPS) configured to act as reverse proxies for C2 traffic associated with the multiple malware families used by the group. These reverse proxy servers are typically configured to listen on standard HTTP(s) ports such as TCP 80, 443, 8080, and 8443) and to redirect traffic to upstream actor-controlled servers. These upstream servers are then likely directly administered by the threat actor using the open-source virtual private network (VPN) software SoftEther.
The group often utilizes a mix of offensive security tools, shared capabilities, and bespoke tooling, including Cobalt Strike, Brute Ratel C4, Winnti, ShadowPad, and the FunnySwitch and Spyder backdoors. Throughout 2022 and 2023, Insikt Group tracked over 100 C2 IP addresses in use by RedHotel, with the group heavily favoring particular hosting providers including AS-CHOOPA (Vultr), G-Core Labs S.A., and Kaopu Cloud HK Limited. Threat actor preference for particular hosting providers is likely influenced by factors such as cost, reliability, ease of setup, data center locations, perceived level of cooperation with or collection from governments and private sector organizations, and the speed and willingness with which hosting providers deal with malicious use of their services.
Recorded Future's Insikt Group observes various Chinese state-sponsored cyber threats, with RedHotel standing out for its broad scope and intensity of activity. RedHotel's campaigns include innovations such as exploiting a stolen code signing certificate and commandeering Vietnamese government infrastructure. Despite public exposure, RedHotel's bold approach suggests it will persist in its activities.
Defense Strategies
Organizations can defend against RedHotel activity by prioritizing hardening and vulnerability patching of internet-facing appliances (particularly corporate VPN, mail server, and network devices), logging and monitoring of these devices, and implementing network segmentation to limit exposure and lateral movement potential to internal networks
Note: This report summary was first published on August 8, 2023 and has been updated on October 29, 2024. The original analysis and findings remain unchanged.
To read the entire analysis with endnotes, click here to download the report as a PDF.
Appendix B — Mitre ATT&CK Techniques
Tactic: Technique
ATT&CK Code
Observable
Reconnaissance: Active Scanning: Vulnerability Scanning
RedHotel has used vulnerability scanning tools such as Acunetix to scan externally facing appliances for vulnerabilities
Resource Development: Acquire Infrastructure: Domains
RedHotel has purchased domains, primarily via Namecheap.
Resource Development: Acquire Infrastructure: Virtual Private Server
RedHotel has provisioned actor-controlled VPS, with a preference for the providers Choopa (Vultr), G-Core, and Kaopu Cloud HK Limited.
Resource Development: Compromise Infrastructure: Server
RedHotel has also used compromised GlassFish servers as Cobalt Strike C2s and to scan target networks.
Initial Access: Exploit Public-Facing Application
RedHotel has exploited public-facing applications for initial access, including Zimbra Collaboration Suite (CVE-2022-24682, CVE-2022-27924, CVE-2022-27925 chained with CVE-2022-37042, and CVE-2022-30333), Microsoft Exchange (ProxyShell), and the Log4Shell vulnerability in Apache Log4J.
Initial Access: Spearphishing: Spearphishing Attachment
RedHotel has used archive spearphishing attachments containing shortcut (LNK) files which fetch remotely hosted scripts (HTA, VBScript). These scripts are then used to trigger DLL search order hijacking infection chains and display decoy documents to users.
Persistence: Server Software Component: Web Shell
RedHotel has used web shells within victim environments and to interact with compromised GlassFish servers
Persistence:: Scheduled Task/Job: Scheduled Task
RedHotel has used scheduled tasks for persistence for the group’s Spyder backdoor:
C:\Windows\System32\schtasks.exe /RUN /TN PrintWorkflow_10e3b
Persistence: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
The ScatterBee ShadowPad loader persists via the Run registry key and also stores the encrypted ShadowPad payload in the registry.
Defense Evasion: Obfuscated Files or Information
RedHotel has used the tool ScatterBee to obfuscate ShadowPad payloads. The group has also repeatedly stored encrypted or encoded payloads within files named bin.config.
Defense Evasion: Deobfuscate/Decode Files or Information
Defense Evasion: Subvert Trust Controls: Code Signing
RedHotel has signed malicious binaries using stolen code signing certificates (such as the referenced WANIN International certificate).
Defense Evasion: Hijack Execution Flow: DLL Search Order Hijacking
RedHotel has abused multiple legitimate executables for DLL search order hijacking, including vfhost.exe, mcods.exe, and BDReinit.exe.
Defense Evasion: Masquerading: Match Legitimate Name or Location
RedHotel has used legitimate file names in tandem with DLL search order hijacking to load malicious DLLs.
Command and Control: Proxy: External Proxy
RedHotel has used VPS C2s to proxy traffic upstream to actor-controlled servers.
Command and Control: Application Layer Protocol: Web Protocols
RedHotel Brute Ratel and Cobalt Strike samples referenced within this report communicate over HTTPS.
Exfiltration: Exfiltration Over C2 Channel
RedHotel has exfiltrated data over malware C2 channels.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/research/redhotel-a-prolific-chinese-state-sponsored-group-operating-at-a-global-scale