Chinese State Hackers Launch Global Cyber Espionage Campaign Against Defense, Aerospace, and Government Targets

# Chinese State-Sponsored Hackers Target Global Organizations in Massive Cyber Espionage Campaign

A sophisticated Chinese state-sponsored hacking group has been conducting an extensive cyber espionage campaign targeting government agencies and private organizations across multiple continents, according to new research from cybersecurity firm Recorded Future.

## The Threat Actor: RedNovember

The hacking group, now designated as **RedNovember** (previously tracked as TAG-100 and Microsoft’s Storm-2077), has been actively targeting high-profile organizations worldwide since June 2024. This Chinese state-sponsored threat actor has demonstrated remarkable reach, conducting operations across Africa, Asia, North America, South America, and Oceania.

## Attack Methods and Tools

RedNovember employs a sophisticated toolkit that includes:

– **Pantegana backdoor**: A Go-based malware framework for post-exploitation activities
– **Spark RAT**: An open-source remote access tool
– **Cobalt Strike**: A legitimate penetration testing tool frequently abused by cybercriminals
– **LESLIELOADER**: A Go-based loader variant used to deploy malicious payloads

The group strategically uses open-source tools to complicate attribution efforts—a common tactic among state-sponsored espionage actors.

## Primary Targets and Victims

The campaign has successfully compromised numerous high-value targets, including:

– **Government entities**: Foreign affairs ministries, state security organizations, and government directorates
– **Defense sector**: At least two U.S. defense contractors and aerospace organizations
– **Private sector**: European engine manufacturers, law firms, and space organizations
– **Media**: Newspaper organizations and engineering contractors

## Attack Vector: Exploiting Security Appliances

RedNovember focuses on compromising internet-facing security devices, exploiting known vulnerabilities in products from major vendors including:

– Check Point (CVE-2024-24919)
– Palo Alto Networks (CVE-2024-3400)
– Cisco, Citrix, F5, Fortinet, Ivanti, and SonicWall

This approach allows the group to bypass traditional security measures by compromising the very systems designed to protect organizations—including VPNs, firewalls, load balancers, and email servers.

## Geographic Focus and Recent Activity

Between June 2024 and May 2025, RedNovember has concentrated its efforts on:

– **Primary targets**: Panama, United States, Taiwan, and South Korea
– **Recent operations**: Targeting Ivanti Connect Secure appliances at U.S.-based organizations
– **Strategic timing**: Attacking South American government systems before diplomatic visits to China

## Infrastructure and Operations

The group maintains operational security by using commercial VPN services like ExpressVPN and Warp VPN to manage their command-and-control infrastructure. They operate two distinct server sets—one for exploiting internet-facing devices and another for communicating with their malware tools.

## Implications

RedNovember’s broad targeting approach suggests evolving intelligence requirements from Chinese state sponsors. The group’s ability to maintain persistent access across diverse sectors and geographic regions demonstrates the sophisticated nature of modern state-sponsored cyber espionage operations.

Organizations worldwide, particularly those in government, defense, and critical infrastructure sectors, should prioritize patching known vulnerabilities in perimeter security devices and implementing robust monitoring for unusual network activity.

Share This Article