RedNovember, a Chinese state-sponsored threat actor also tracked as Storm-2077, has conducted a widespread cyber espionage campaign targeting government and private sector organizations across multiple continents. The group leveraged publicly available proof-of-concept exploits for vulnerabilities in perimeter appliances from vendors such as Check Point, Cisco, Citrix, F5, Fortinet, Ivanti, Palo Alto Networks, and SonicWall to gain initial access. RedNovember deployed the Go-based backdoor Pantegana and Cobalt Strike during its intrusions, compromising entities including ministries, defense contractors, and intergovernmental organizations. Security researchers highlight the group's rapid adoption of newly disclosed vulnerabilities and its alignment with Chinese state interests, emphasizing the risks posed by the public release of exploit code.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In September 2025, Recorded Future assessed the actor previously tracked as TAG100 as highly likely Chinese state-sponsored and began tracking it as RedNovember. The report also linked the group to malware infrastructure overlapping with Google Mandiant-tracked UNC5266 and detailed its use of LeslieLoader, SparkRAT, Pantegana, and Cobalt Strike.
By July 2025, the campaign had affected organizations across the Americas, Asia, Africa, Europe, and Oceania, including at least two U.S. defense contractors, a European government directorate, and entities in aerospace, legal, energy, and government sectors. Reporting says the activity ran from June 2024 through July 2025 and relied on compromised VPNs, firewalls, and other edge devices.
In April 2025, RedNovember targeted 30 Panamanian organizations during a visit by U.S. Defense Secretary Pete Hegseth. The targeting was cited as another example of the group's operations tracking sensitive geopolitical developments.
The group was detected conducting activity in December 2024 during a surprise Chinese military exercise around Taiwan, indicating operations aligned with geopolitical events. Reporting describes this as reconnaissance or intrusion activity tied to Taiwan-related intelligence collection.
Recorded Future's Insikt Group first observed the threat actor later renamed RedNovember in July 2024. Early activity showed compromises of internet-facing edge devices and targeting of exposed collaboration and email systems for persistent access.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcethecyberthrone.in
Open sourcego.theregister.com
Open sourcebankinfosecurity.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.