A sophisticated Chinese state-sponsored hacking group has been conducting an extensive cyber espionage campaign targeting government agencies and private organizations across multiple continents, according to new research from cybersecurity firm Recorded Future.
## The Threat Actor: RedNovember
The hacking group, now designated as **RedNovember** (previously tracked as TAG-100 and Microsoft’s Storm-2077), has been actively targeting high-profile organizations worldwide since June 2024. This Chinese state-sponsored threat actor has demonstrated remarkable reach, conducting operations across Africa, Asia, North America, South America, and Oceania.
## Attack Methods and Tools
RedNovember employs a sophisticated toolkit that includes:
– **Pantegana backdoor**: A Go-based malware framework for post-exploitation activities
– **Spark RAT**: An open-source remote access tool
– **Cobalt Strike**: A legitimate penetration testing tool frequently abused by cybercriminals
– **LESLIELOADER**: A Go-based loader variant used to deploy malicious payloads
The group strategically uses open-source tools to complicate attribution efforts—a common tactic among state-sponsored espionage actors.
## Primary Targets and Victims
The campaign has successfully compromised numerous high-value targets, including:
– **Government entities**: Foreign affairs ministries, state security organizations, and government directorates
– **Defense sector**: At least two U.S. defense contractors and aerospace organizations
– **Private sector**: European engine manufacturers, law firms, and space organizations
– **Media**: Newspaper organizations and engineering contractors
## Attack Vector: Exploiting Security Appliances
RedNovember focuses on compromising internet-facing security devices, exploiting known vulnerabilities in products from major vendors including:
– Check Point (CVE-2024-24919)
– Palo Alto Networks (CVE-2024-3400)
– Cisco, Citrix, F5, Fortinet, Ivanti, and SonicWall
This approach allows the group to bypass traditional security measures by compromising the very systems designed to protect organizations—including VPNs, firewalls, load balancers, and email servers.
## Geographic Focus and Recent Activity
Between June 2024 and May 2025, RedNovember has concentrated its efforts on:
– **Primary targets**: Panama, United States, Taiwan, and South Korea
– **Recent operations**: Targeting Ivanti Connect Secure appliances at U.S.-based organizations
– **Strategic timing**: Attacking South American government systems before diplomatic visits to China
## Infrastructure and Operations
The group maintains operational security by using commercial VPN services like ExpressVPN and Warp VPN to manage their command-and-control infrastructure. They operate two distinct server sets—one for exploiting internet-facing devices and another for communicating with their malware tools.
## Implications
RedNovember’s broad targeting approach suggests evolving intelligence requirements from Chinese state sponsors. The group’s ability to maintain persistent access across diverse sectors and geographic regions demonstrates the sophisticated nature of modern state-sponsored cyber espionage operations.
Organizations worldwide, particularly those in government, defense, and critical infrastructure sectors, should prioritize patching known vulnerabilities in perimeter security devices and implementing robust monitoring for unusual network activity.
