In the lead-up to APNIC60, where Chief Technical Officer Leslie Daigle will give a keynote address, we’re publishing a series of articles that address regionally meaningful threats beyond the well-documented Chinese-origin attacks. We present four distinct Asia-linked campaigns based on attacks seen directly in AIDE or confirmed by matching public reports. Each case offers a different lens on the threat landscape—ranging from geopolitical motivations to financial disruption and targeted espionage. Our goal is to provide context, elevate regional perspectives, and set the stage for deeper discussion during the keynote. This is the third article in the series; we previously examined Pakistani-based APT36 and North Korea-based Kimsuky.
Introduction
Cryptocurrency mining malware is often dismissed as background noise, an irritation that consumes resources but poses little strategic risk. The RedTail campaign, a sophisticated and financially motivated operation, challenges that assumption.
From February to August 2025, the Global Cyber Alliance’s AIDE honeypot network recorded a sustained cryptomining operation that stood apart from routine cybercrime. AIDE is a distributed system covering 25 countries with around 200 sensors. Running on GCA’s ProxyPot technology since November 2024, it emulates service protocols such as SSH, Telnet, FTP, HTTP/HTTPS, and SMTP to capture attacker behavior in controlled environments.
RedTail exploited known vulnerabilities, deployed customized binaries across multiple architectures, and maintained active infrastructure for months at a time. These are the hallmarks of a planned campaign, executed with persistence and discipline more commonly associated with state-aligned threat actors.
What makes RedTail especially significant is its resemblance to the Lazarus Group, a North Korea–linked actor known for financially motivated intrusions. Recent Lazarus operations have included the $1.46 billion Ethereum theft from Bybit, showcasing unprecedented laundering speed and scale. RedTail’s ability to attack different types of systems, much like Lazarus did in its high-profile AppleJeus campaign, suggests a level of planning and expertise far beyond ordinary cybercriminal activity.
The Hidden Digital Economy
The insights presented here reflect AIDE’s observations between February and August 2025 and may undercount broader real-world exposure. Through AIDE, we recorded 13,627 RedTail probe-and-exploit attempts across 25 countries during the six-month period. Over one-third of these targeted Asia-Pacific economies, with India, Australia, and Singapore most frequently affected. RedTail operators exploited vulnerabilities such as CVE-2024-3400 (PAN-OS) and CVE-2024-4577 (PHP) to establish access.
RedTail’s activity clustered around financial and technology hubs. Even though AIDE captures attacks in controlled environments, the persistence and coordination suggest real-world infrastructure would be at risk.

How the Campaign Unfolded: Phased Escalation
AIDE’s timeline shows that RedTail followed a structured campaign lifecycle. Activity began with reconnaissance in February (136 attacks), escalated to a peak in April (3,741 attacks), dropped into a sustainment phase in June (790 attacks), and resurged in July (3,131 attacks) before winding down in late August.
This represents a 27-fold escalation from reconnaissance to peak, followed by sustained activity and resurgence. Such a deliberate tempo demonstrates planning and resource management that go well beyond opportunistic cybercrime.

How RedTail Reached Its Targets: Attack Flows
RedTail traffic did not flow directly from attacker systems to victims. Instead, the majority of attack flows were routed through multiple proxy layers before reaching their targets. Nearly three-quarters of the traffic directed at Asia-Pacific systems passed through non-regional intermediaries.
This reliance on layered routing underscores a deliberate focus on operational security and obfuscation. By disguising the true origin of activity, RedTail operators reduced the chances of rapid attribution and made defensive blocking more difficult.

Persistence in AIDE Data
AIDE data highlights not only the scale of RedTail but also the persistence of its infrastructure. When attacker nodes are ranked by longevity rather than raw attack counts, a clear picture emerges: several nodes were active for nearly the entire 26-week observation period, others for 20 to 24 weeks, and even the least persistent remained active for over two months.
Maintaining infrastructure across this length of time requires continuous investment and coordination. Such persistence reflects discipline and durability that are more consistent with state-sponsored operations than with short-lived cybercriminal campaigns.

Tactical Convergence with Lazarus Group
Several RedTail patterns captured by AIDE bear a strong resemblance to the tradecraft documented in Lazarus Group operations.
AIDE repeatedly recorded the deployment of RedTail binaries, including redtail.arm7, redtail.arm8, redtail.i686, and redtail.x86_64. This mirrors the cross-platform approach seen in Lazarus’s AppleJeus campaigns, where tailored payloads for multiple architectures enabled compromise across servers, IoT devices, and cloud workloads.
Attack sessions also revealed a consistent reliance on scripts. Many followed the same sequence, beginning with the upload of clean.sh, followed by the placement of multiple RedTail binaries, and concluding with setup.sh. This pattern reflects a persistence doctrine similar to that used by Lazarus, where automation ensures repeatable access while reducing the need for manual operator intervention.
All command and control traffic captured in AIDE was tunneled through encrypted channels, specifically SFTP and SSH. This disciplined use of encryption reflects Lazarus’s operational security practices, which aim to make monitoring and detection more difficult.
AIDE further showed that RedTail routed activity through layers of proxy infrastructure, disguising the true origin of attacks. This method is consistent with Lazarus’s long-standing practice of masking source systems behind multi-hop chains of intermediaries.
Finally, RedTail directed its mining operations to private Monero pools instead of public services. This investment in custom financial infrastructure reflects the same philosophy Lazarus has demonstrated in maintaining independent revenue channels.
Taken together, these patterns reveal a level of automation, persistence, and operational discipline that is not typical of opportunistic cybercrime.
While these operational overlaps do not constitute definitive attribution, they demonstrate a level of sophistication typically associated with well-resourced, state-aligned threat actors.

Closing: APT-Grade Cryptomining
RedTail is not just another cryptomining nuisance. Its sustained six-month campaign across 25 countries, with nearly 40 percent of activity directed at sensors in India, Australia, and Singapore, demonstrates how sophisticated cryptomining operations can pose strategic threats beyond typical cybercrime. The campaign’s use of private mining pools for financial gain underscores why this matters. AIDE’s data revealed a global operation with strong Asia-Pacific concentration, a phased lifecycle moving from reconnaissance through escalation and sustainment, and tradecraft more consistent with APT actors than ordinary cybercriminal groups.
Call to Action
To counter threats of this scale, no single organization can act alone. Defenders should:
- Share intelligence broadly across sectors and borders, ensuring IOCs (Indicators of Compromise) such as RedTail binaries and scripts are circulated quickly.
- Strengthen monitoring and detection for unauthorized cryptomining activity, especially across cloud and edge environments.
- Invest in resilience by prioritizing patching of widely exploited vulnerabilities.
By taking these steps, the community can raise the cost of operations for adversaries like RedTail and blunt the impact of future APT-grade cryptomining campaigns.
If you are interested in AIDE and our efforts to reduce unwanted traffic on the internet, we invite you to contact us to collaborate.
References
- The Hacker News: RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall Flaw
https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html - Akamai Security Research: RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit
https://www.akamai.com/blog/security-research/2024-redtail-cryptominer-pan-os-cve-exploit - MITRE ATT&CK® Group G0032: Lazarus Group
https://attack.mitre.org/groups/G0032/ - CyberScoop: Bybit Lazarus Group $1.46B Ethereum Theft
https://cyberscoop.com/bybit-lazarus-group-north-korea-ethereum/ - NVD – CVE-2024-3400 (PAN-OS)
https://nvd.nist.gov/vuln/detail/CVE-2024-3400 - NVD – CVE-2024-4577 (PHP)
https://nvd.nist.gov/vuln/detail/CVE-2024-4577 - IBM: What is Cryptojacking?
https://www.ibm.com/think/topics/cryptojacking - Monero: Mining Monero
https://www.getmonero.org/get-started/mining/ Cryptojacking Hits Industry Hard and - Hospitals Could Be Next – Cyber Magazine
https://cybermagazine.com/articles/cryptojacking-hits-industry-hard-and-hospitals-could-be-next - What is Cryptojacking? Types & Real World Examples – SentinelOne
https://www.sentinelone.com/cybersecurity-101/cybersecurity/cryptojacking/



