r3dm0v3
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias r3dm0v3 has been linked to a single publicly reported cyber incident that occurred on April 6, 2016. The target of that incident was Watsons Auctioneers, a company based in the United Kingdom. According to the available reporting, the attack resulted in the compromise of confidential information stored on the victim’s systems. The integrity and availability of the affected data were not confirmed to have been altered as part of the incident. The motive behind the activity was assessed to be personal gain.
The tactics described in the reporting focus on exfiltration from end hosts, indicating that the actor sought to copy data directly from user devices. The specific technique involved targeting those devices to steal information, with no mention of malware deployment or persistence mechanisms. No details were provided about the use of particular malware families, custom tools, or specific command‑and‑control infrastructure. The incident narrative does not reference any denial‑of‑service activity or modification of data, aligning with the observed confidentiality‑only impact. Consequently, the known TTP profile for r3dm0v3 is limited to data‑theft via host‑based exfiltration.
Attribution information for r3dm0v3 is sparse, with the only geographic detail being that the actor is located in China, as noted in the threat actor context. No public sources have tied the alias to a state‑sponsored program, a criminal consortium, or any broader affiliations. The 2016 Watsons Auctioneers breach remains the sole publicly documented operation associated with r3dm0v3. No additional campaigns, tools, or victim sectors have been reported in open‑source material. This concludes the factual profile based exclusively on the supplied information.
Incidents
Attributed incidents are available to members.
1 incident