Red Rabbit Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Red Rabbit Team is a threat actor group that has been referenced in open‑source reporting under that alias. The group is associated with the location of China, as indicated in the available background information. It first came to public attention in early 2021 when it began making claims about compromising Indian telecommunications data. Over a period of fifteen months the group interacted with the security teams of the targeted organization, presenting a series of varying statements. Despite the repeated outreach, the group has not provided verifiable proof of a nationwide database compromise.
The claims made by Red Rabbit Team have focused on the telecommunications sector in India, specifically referencing Airtel and its subscriber base. They asserted access to more than 2.5 million Airtel subscriber records, yet the company denied a full breach and noted that only a short video of the SDR portal appeared genuine. The group also referenced possible exposure of subscriber data from the Jammu and Kashmir region, although they failed to demonstrate how the complete set was obtained. In a separate incident, the actor’s name appeared in connection with a Malaysian e‑payment provider, where a forum listing offered for sale accounts said to belong to E‑Pay Malaysia. The listing described the data as containing names, e‑mail addresses, dates of birth, contact addresses and mobile phone numbers, with passwords reportedly masked. The parent company, GHL Systems, stated that the alleged breach was limited to its E.V.E. payment system and did not affect other services.
Because the reporting does not describe any specific malware families, exploit tools, or initial‑access vectors used by Red Rabbit Team, no technical tactics can be confirmed from the source material. Likewise, no public attribution links the group to a state sponsor, criminal consortium, or any other affiliation, so such connections remain unspecified. The only concrete operations that can be cited are the alleged Airtel data‑claims and the Malaysian e‑payment account listing, both of which remain unverified and are disputed by the respective organizations. These points constitute the extent of the factual information available about Red Rabbit Team based on the provided sources.
Incidents
Attributed incidents are available to members.
1 incident