Skip to main content
Mallory
MalwareRansomwareUsed by 1 actor

Pantegana

Pantegana is a Go-based backdoor and command-and-control (C2) framework/RAT used in RedNovember operations, a cluster that Recorded Future assesses as highly likely Chinese state-sponsored and that Microsoft tracks as Storm-2077. Reporting describes RedNovember using Pantegana alongside Cobalt Strike, SparkRAT, and LESLIELOADER after compromising internet-facing edge devices and other perimeter systems. Observed initial access and targeting associated with the broader activity include vulnerable VPNs, firewalls, Outlook Web Access, Ivanti Connect Secure, Palo Alto Networks GlobalProtect, SonicWall, Cisco ASA, F5 BIG-IP, Sophos SSL VPN, and Fortinet FortiGate, as well as 3CX and Zimbra in some cases. Pantegana is described as an open-source post-exploitation framework with obfuscation capabilities and as RedNovember’s C&C framework. The activity targeted high-profile government and private-sector organizations globally, including government and diplomatic entities, defense and aerospace organizations, space-related entities, law firms, manufacturing, technology, oil and gas, and research organizations across the U.S., Panama, Asia, Europe, Africa, and Oceania. One reported infrastructure indicator is RedNovember server 198.98.50.218, which was observed also hosting a Pantegana C2. A 2026 memory-forensics paper evaluating Go malware included Pantegana RAT and reported recovery of runtime artifacts such as C2 endpoints from memory.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
RedNovember

...the compromise of vulnerable VPNs, firewalls, and other security solutions with Pantegana and Spark RAT...

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

Key initial access vectors include vulnerabilities in internet-facing perimeter devices: SonicWall, Cisco ASA, Fortinet, F5 BIG-IP, and Palo Alto Networks appliances ... Exposed Outlook Web Access (OWA) and VPN infrastructure

T1071Application Layer ProtocolEvidence1

C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/C2 infrastructure.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.