Skip to main content
Mallory
5 malware familiesExploits CVEs in the wild

RedNovember

Also known asRedNovemberStorm-2077TAG-100

RedNovember is a threat actor also tracked as Storm-2077 and TAG-100. Recorded Future assesses it is highly likely a Chinese state-sponsored threat activity group, and multiple cited sources describe it as a Chinese state or nation-state espionage actor active since at least January 2024 or mid-2024. The group has conducted cyberespionage against high-profile government and private-sector organizations globally, with reported targeting across the U.S., Panama, Taiwan, South Korea, Europe, Southeast Asia, Africa, Oceania, and the broader Americas and Asia. Reported victim sectors include government, diplomatic entities, defense, aerospace, space, telecommunications, aviation, financial and legal services, manufacturing, technology, oil and gas, and research organizations. RedNovember is reported to focus heavily on initial access through internet-facing edge and perimeter systems. Observed or reported targets include Cisco ASA, F5 BIG-IP, Palo Alto Networks devices including GlobalProtect, Fortinet FortiGate, Sophos SSL VPN, SonicWall, Ivanti Connect Secure, Check Point VPN gateways, Outlook Web Access, Zimbra, and 3CX. Multiple reports state the actor rapidly exploits newly disclosed vulnerabilities and public proof-of-concept exploit code, especially against edge devices, rather than being primarily associated with zero-day use. Its tooling and post-compromise tradecraft rely heavily on commodity and open-source capabilities. Reported tools include the Go-based backdoor or C2 framework Pantegana, Cobalt Strike, SparkRAT, and a Go-based loader called LESLIELOADER or Leslieloader used to deploy SparkRAT. Reported malware capabilities include file transfer, system fingerprinting, and interactive command execution across Windows, Linux, and macOS. Microsoft also reported phishing for credential theft, likely exploitation of edge-facing devices for initial access, and techniques focused on email data theft, including abuse of cloud applications such as eDiscovery and creation of malicious applications with mail-read permissions. Other reporting notes credential harvesting, persistence, reconnaissance, and long-running access to some victims. The group’s operations are repeatedly described as aligning with Chinese strategic and geopolitical interests. Reported activity includes targeting in Taiwan and Panama in proximity to geopolitical and military events of interest to China, reconnaissance against more than 30 Panamanian government organizations in April 2025, and activity observed during a December 2024 Chinese military exercise around Taiwan. Recorded Future also reported overlap or shared malware infrastructure with the China-linked cluster UNC5266. No sub-groups are directly identified in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • defense
  • aerospace
  • legal
MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics5 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0001
Initial Access
2 techniques
T1133
External Remote Services
T1190×2
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1133
External Remote Services
TA0008
Lateral Movement
1 technique
T1021×2
Remote Services
ACTIVITY FEED

Recent activity

18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cloudatg insightsNews
Feb 13, 2026
AI Development & Software Engineering | CloudATG

Suspected China state-sponsored espionage cluster targeting global government and private-sector organizations; reported using Pantegana and Cobalt Strike.

Read more
register securityNews
Dec 9, 2025
As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs

RedNovember is a Chinese government-sponsored espionage group known for targeting defense, electronics, and manufacturing companies, likely for the purposes of intellectual property theft and long-term espionage. While there is no public evidence of them specifically targeting robotics firms yet, their modus operandi aligns with targeting sectors prioritized in China's five-year plans, which now include AI and smart robotics.

Read more
alphahunt blogNews
Nov 6, 2025
Will RedNovember be publicly reported to exploit at least one zero-day vulnerability in 2026? Updated 2025-11-06

Forecast-focused discussion of RedNovember’s likely evolution from PoC-driven N-day exploitation of edge devices (VPN/firewall gateways) toward potential zero-day use in 2026; notes attribution/rebranding risk and emphasizes edge-appliance stealth access as the operational objective.

Read more
alphahunt blogNews
Oct 7, 2025
Will RedNovember be publicly reported to exploit at least one zero-day vulnerability in 2026?

RedNovember is a China-nexus espionage threat actor known for targeting edge devices using N-day vulnerabilities and public proof-of-concept exploits, with a focus on government, defense, and technology organizations. While their tradecraft has primarily relied on exploiting known vulnerabilities, there is a plausible risk they may pivot to using zero-day exploits, following the precedent set by other China-nexus groups.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.