Between June 2024 and July 2025, a Chinese state-sponsored threat group compromised or attempted to compromise perimeter appliances at government agencies, defense contractors, aerospace organizations, space research entities, and law firms across at least a dozen countries. The group is now called RedNovember. Recorded Future previously tracked the same activity as TAG-100. Microsoft tracks overlapping activity as Storm-2077.
Every major cybersecurity publication has covered the initial-access story. Fewer have addressed what actually matters after a firewall or VPN gateway falls: what an espionage actor does with that foothold, and why controlling data movement remains the meaningful defense once the perimeter has been bypassed.
RedNovember is a Chinese state-sponsored cyber-espionage group tracked by Recorded Future’s Insikt Group. The group exploits vulnerabilities in internet-facing devices to establish initial access, then uses open-source tools and commercial red-team frameworks for post-exploitation activity.
The naming history matters because the same activity appears under multiple designations across the threat intelligence community.
In July 2024, Recorded Future publicly reported on an activity cluster it called TAG-100. At that time, the researchers documented suspected cyber-espionage activity but did not attribute it to a specific country. The reporting covered exploitation of internet-facing appliances and use of the Pantegana Go-based backdoor.
Over the following year, additional intelligence and attribution analysis led Recorded Future to reassess the cluster. In September 2025, the firm published its findings and moved the activity to a new designation: RedNovember. The updated assessment concluded that TAG-100 activity is highly likely Chinese state-sponsored.
The two names describe overlapping activity tracked by different vendors using different visibility.
Microsoft tracks activity it calls Storm-2077 and attributes to a China state actor focused on intelligence collection. Recorded Future explicitly notes that RedNovember overlaps with Storm-2077. Microsoft has separately said Storm-2077 overlaps with activity tracked elsewhere as TAG-100.
The naming picture:
| Researcher | Tracking Name | Attribution |
|---|---|---|
| Recorded Future / Insikt Group | RedNovember (formerly TAG-100) | Highly likely Chinese state-sponsored |
| Microsoft | Storm-2077 | China state actor |
| Malpedia | Storm-2077 / RedNovember / TAG-100 | Aggregated vendor tracking |
Threat-actor clustering is inherently messy. Different vendors see different portions of an operation and cluster the activity slightly differently. Presenting these names as fully synonymous overstates the certainty of the mapping. What can be said confidently: the three names describe activity that substantially overlaps, and all three researchers assess it as Chinese state-sponsored.
RedNovember pursues intelligence, not disruption. Recorded Future’s victimology concentrates around government, aerospace and defense, and professional services. Microsoft assesses Storm-2077’s objective as intelligence collection.
The observed target set includes:
The geographic footprint is global. Recorded Future documented targeting in the United States, Taiwan, South Korea, Japan, the United Kingdom, Germany, Brazil, Portugal, Italy, Canada, Panama, and other countries across Africa, Asia, Europe, and the Americas.
Most coverage of edge-device compromise stops at the intrusion. That leaves the most important question unanswered: what does an espionage actor take once inside?
Email is often the answer.
Corporate and government email systems contain:
Microsoft has specifically documented Storm-2077 successfully exfiltrating emails after harvesting valid credentials, including through legitimate cloud applications such as eDiscovery tooling. That last part is important. Once an attacker has authenticated as a trusted user, malicious activity can move through applications that look entirely legitimate to the organization’s security tooling.
For espionage actors, compromising infrastructure is a means to an end. The prize is the information that infrastructure holds.
The campaign spans roughly 13 months of documented activity, with distinct phases and target sets.
Recorded Future’s July 2024 reporting on TAG-100 documented exploitation of internet-facing appliances, use of the open-source Pantegana backdoor, SparkRAT, and Cobalt Strike, and targeting of government and intergovernmental organizations. Palo Alto GlobalProtect exploitation activity was among the observed patterns.
Following the publication of proof-of-concept code for CVE-2024-24919, activity attributed to the group touched VPN gateways at approximately 60 organizations. Recorded Future treats exploitation as plausible based on timing rather than confirmed in every instance.
Broad scanning against U.S. and global aerospace and defense infrastructure. Recorded Future explicitly noted it did not see evidence of successful compromise from this particular reconnaissance activity. That distinction matters and should not be glossed over: reconnaissance and successful intrusion are separate stages.
Activity focused on Taiwan military and semiconductor-adjacent targets, plus South Korean organizations in financial and scientific sectors. Some intrusions coincided with military drills around Taiwan in December 2024.
A particularly active period. Documented targeting included:
The Panama focus coincided with U.S. diplomatic visits to the country, illustrating how RedNovember activity often tracks geopolitical events of strategic interest to China.
Recorded Future publicly connected the TAG-100 activity to the new RedNovember designation and formally assessed it as highly likely Chinese state-sponsored.
The most consistent pattern across the campaign is exploitation of internet-facing infrastructure.
Perimeter security appliances have become primary targets for state-sponsored espionage. Recorded Future documented RedNovember targeting or interest in:
The math is straightforward. Edge devices are internet-facing by definition, hold high privilege on the internal network, sit at the boundary of enterprise traffic flows, and often run with limited security telemetry compared to endpoints. Many appliances have slow patch cycles because they cannot be easily rebooted or updated during business hours. Some are effectively black boxes that security teams cannot fully instrument.
The result: internet-facing appliances offer a high-value target with lower detection risk than compromising internal endpoints one at a time.
The device purchased to protect the network can itself become the doorway into it. That is the strategic problem RedNovember illustrates. Perimeter hardening remains necessary, but perimeter hardening alone is no longer sufficient defense against espionage actors who treat edge infrastructure as their preferred target set.
A distinctive operational trait of the group is the speed at which it moves against newly disclosed vulnerabilities once proof-of-concept exploit code becomes publicly available.
The pattern:
A Palo Alto Networks GlobalProtect vulnerability that saw reconnaissance and exploitation activity shortly after disclosure.
A Check Point VPN gateway vulnerability. Activity attributed to the group touched approximately 60 organizations’ VPN gateways after the PoC became public.
The Microsoft Follina vulnerability appeared in RedNovember-related malicious-document activity, showing that edge exploitation is not the group’s only entry vector.
Vulnerability summary:
| Vulnerability | Technology | Observed RedNovember Use | Security Lesson |
|---|---|---|---|
| CVE-2024-3400 | Palo Alto GlobalProtect | Recon and exploitation activity | Patch exposed appliances rapidly |
| CVE-2024-24919 | Check Point VPN | Targeting soon after PoC release | PoC publication shrinks response windows |
| CVE-2022-30190 | Microsoft Follina | Malicious-document delivery chains | Edge exploitation isn’t the only vector |
The operational lesson: the window between vulnerability disclosure and observed exploitation activity by state-sponsored actors is now measured in days, sometimes hours. Enterprise patching cadences built around monthly maintenance windows cannot keep pace.
The group’s toolset is distinctive for what it lacks. There is no signature custom malware family. Instead, RedNovember composes attacks from open-source tools and widely available commercial red-team frameworks. That choice reduces cost, complicates attribution, and provides operational flexibility.
An open-source, Go-based, cross-platform backdoor. Its reported capabilities include:
The file upload and download capabilities matter for the espionage mission. Pantegana is designed to move data.
A Go-based loader used to deliver secondary payloads. Recorded Future observed LESLIELOADER delivering both SparkRAT and Cobalt Strike Beacon on compromised systems.
An open-source remote administration tool used within the broader intrusion toolkit. Its inclusion illustrates the group’s preference for repurposing publicly available capabilities rather than developing proprietary malware.
A commercial red-team framework that provides flexible post-exploitation capability. Cobalt Strike is widely abused by both criminal and state-sponsored actors. Its presence in RedNovember intrusions provides advanced capability without the operational overhead of custom development.
One important note on tool attribution. Some secondary coverage attributes specific post-exploitation techniques to RedNovember that read closer to general Cobalt Strike or commodity post-exploitation possibilities than behaviors documented as RedNovember-specific in primary reporting. Observed activity and technical capability are not the same thing. This article stays with what Recorded Future and Microsoft have documented directly.
Understanding how initial compromise turns into intelligence loss requires walking the full chain.
Stage 1: Reconnaissance. The group scans internet-facing infrastructure to identify exposed appliances at organizations of interest.
Stage 2: Vulnerability identification. Appliance versions are fingerprinted to identify targets vulnerable to known or newly disclosed exploits.
Stage 3: Exploitation of public-facing infrastructure. VPN, firewall, email portal, or collaboration server is compromised through a known vulnerability, often shortly after PoC publication.
Stage 4: Command and control established. Pantegana, LESLIELOADER, SparkRAT, or Cobalt Strike Beacon provides ongoing access to the compromised environment.
Stage 5: Persistence and access expansion. The foothold is maintained. Valuable internal systems are identified.
Stage 6: Credential and session harvesting. This stage becomes especially important when considering the overlapping Storm-2077 activity Microsoft documented. Valid credentials and session tokens are collected from compromised endpoints and used to authenticate to additional systems.
Stage 7: Internal or cloud resource access. Mail systems, file repositories, applications, and collaboration platforms are reached using stolen credentials.
Stage 8: Intelligence collection. Emails, documents, credentials, intellectual property, and other sensitive information are identified and staged.
Stage 9: Exfiltration. Data is removed from the environment through attacker-controlled infrastructure or abused legitimate channels.
The final three stages are where the espionage mission is actually accomplished. Everything before them is preparation.
Microsoft’s documentation of Storm-2077 activity provides visibility into a phase most coverage of RedNovember does not develop.
Microsoft observed Storm-2077:
The implication is significant. Once attackers obtain a trusted identity, malicious activity may move through legitimate enterprise applications rather than through obviously malicious infrastructure. A signed-in user reading email through a normal application looks nothing like an intrusion in progress. That is precisely the point.
Detecting espionage after credential compromise requires visibility into what authenticated identities actually do: which files they access, what data they move, whether the volume and pattern of access matches the user’s normal behavior.
The group’s targeting of the defense industrial base and adjacent sectors is well documented and worth addressing directly.
Recorded Future observed:
Between June 2024 and July 2025, the group targeted 28 U.S. organizations with particular focus on prominent aerospace and defense targets. Recorded Future noted that its threat hunters found no evidence of successful compromise from that specific targeting activity, though the attempted intrusions illustrate the campaign’s expanding scope.
The data held by defense and aerospace organizations includes:
This is not a claim that RedNovember has extracted all of these categories of data. It is a description of the intelligence targets defense-sector security architectures need to protect against actors like RedNovember.
The group’s targeting extends beyond the primary organizations holding classified or high-value data. Compromise attempts have touched:
That pattern reflects an operational reality. An attacker does not have to compromise the organization holding the final classified asset. Attackers can pursue organizations in the ecosystem around that asset, where security controls may be weaker and the same sensitive information may still be accessible.
Modern defense and aerospace work depends on constant exchange of files between organizations:
The security boundary that needs to be defended extends far beyond one company’s firewall. The file transfer channels between organizations become part of the attack surface, and control over what moves through those channels becomes part of the defense.
Most RedNovember coverage ends with familiar recommendations: patch faster, monitor edge devices, deploy MFA, block indicators of compromise.
These recommendations are correct. They are also incomplete.
The missing question: what happens if the attacker gets in anyway?
Recorded Future itself recommends segmentation, restricted access to sensitive data, and defense-in-depth after edge exploitation. Those recommendations point to a broader security architecture that assumes initial access will sometimes succeed and focuses on limiting what compromised access can accomplish.
That architecture includes:
PacGenesis specializes in exactly this layer of the security architecture. Enterprise file transfer built on IBM Aspera provides the controlled channel, authentication, authorization, encryption, and audit trails that make data movement visible and governable. Learn more about malware protection in enterprise file transfers.
Recorded Future observed RedNovember infrastructure interacting with several file-sharing platforms including Filemail and Gofile.io. The reporting suggests possible use of these services in some instances rather than establishing that every service was used for confirmed exfiltration.
The point is not that these platforms are malicious. The point is that they are ordinary. Cloud storage and file-transfer services are used by millions of legitimate business workflows every day, which is exactly why they can be effective exfiltration channels for attackers who have already compromised an authenticated identity.
Organizations need visibility into who is moving what, where, and under whose authorization. That visibility becomes the meaningful detection layer once attackers begin using legitimate-looking infrastructure to move data out.
Detection improves when it is organized around attack stages rather than dumped into a generic indicator list.
Edge detection:
Command-and-control detection:
Identity detection:
Data detection:
This framework is more useful than pushing IOCs into a monitoring platform without context. Detection engineering that maps to attack stages catches the activity even when specific indicators change.
Prioritized defense hierarchy:
Priority 1: Inventory every internet-facing appliance. Unknown exposure cannot be defended. Complete asset inventory is the prerequisite for everything else.
Priority 2: Patch exploited edge vulnerabilities quickly. Especially once public exploit code exists. The window from PoC publication to observed exploitation activity is often measured in days.
Priority 3: Centralize edge-device logging. VPN, firewall, and gateway telemetry needs to flow into the SOC. Appliances with limited logging require additional monitoring at the network layer.
Priority 4: Remove unnecessary external interfaces. Recorded Future explicitly recommends reducing exposed interfaces and portals to the minimum required for business operations. Every exposed service is a potential entry point.
Priority 5: Segment edge infrastructure from sensitive systems. Compromise of a perimeter appliance should not grant automatic access to internal file repositories, cloud environments, or sensitive applications.
Priority 6: Enforce MFA and privileged-access controls. MFA does not fully defeat session token theft, but it substantially raises the cost of credential-based intrusion.
Priority 7: Monitor credentials and cloud sessions. Watch for token replay, unusual session behavior, and OAuth application creation.
Priority 8: Monitor file and data movement. Bulk transfers, first-time destinations, and volume anomalies deserve investigation.
Priority 9: Restrict sensitive data access by role. Least privilege applied at the data layer limits blast radius when identity controls fail.
Priority 10: Monitor third parties and supply-chain access. Trusted partners with credentials into your environment inherit your risk model.
Three strategic lessons stand out from the campaign as documented across Recorded Future and Microsoft reporting.
The network edge is now a primary attack surface. Security infrastructure itself has become an attractive foothold for espionage actors. Perimeter appliances hold high privilege, sit in the traffic path, and often have limited detection capability. Defending them requires the same rigor traditionally applied to endpoints, plus faster patching, plus segmentation that assumes eventual compromise.
Open-source tools do not mean unsophisticated threat actors. RedNovember illustrates how a state-backed actor can achieve strategic objectives using inexpensive, publicly available capabilities. Recorded Future specifically highlighted the group’s combination of public PoC exploits and open-source frameworks. That combination lowers operational cost, complicates attribution, and provides flexibility. It does not indicate lack of capability.
Preventing initial access is only half the job. The actual goal of espionage is information. Perimeter defense reduces the frequency of successful intrusion. It does not eliminate it. Organizations that only build defenses at the entry points are betting entire security postures on never allowing an intrusion to succeed. Organizations that also control what authenticated identities can access, what data can move through file transfer channels, and where that data can be sent give themselves detection and containment options even when initial access succeeds.
That last point is the PacGenesis thesis. Secure file transfer, controlled data movement, and file-level security are not replacements for perimeter defense. They are the layer that continues to work when perimeter defense fails.
What is RedNovember? RedNovember is a Chinese state-sponsored cyber-espionage group tracked by Recorded Future’s Insikt Group. It exploits internet-facing devices to establish initial access, then uses open-source tools and commercial red-team frameworks including Pantegana, SparkRAT, LESLIELOADER, and Cobalt Strike for post-exploitation activity.
Is RedNovember the same as TAG-100? Yes. Recorded Future previously tracked the activity as TAG-100. Following additional attribution analysis, the firm renamed the cluster RedNovember and assessed it as highly likely Chinese state-sponsored.
Is RedNovember the same as Storm-2077? The activity overlaps significantly. Recorded Future says RedNovember overlaps with Microsoft’s Storm-2077 tracking. Microsoft says Storm-2077 overlaps with activity tracked elsewhere as TAG-100. The two names describe substantially overlapping activity clustered slightly differently by each vendor.
Is RedNovember a Chinese state-sponsored group? Recorded Future assesses RedNovember as highly likely Chinese state-sponsored. Microsoft attributes the overlapping Storm-2077 activity to a China state actor.
What organizations does RedNovember target? Documented targets include government ministries, intergovernmental organizations, defense contractors, aerospace and space organizations, semiconductor research entities, telecommunications firms, nuclear and scientific research facilities, legal services, and news organizations across multiple countries.
What vulnerabilities has RedNovember exploited? Recorded Future documented activity related to CVE-2024-3400 (Palo Alto GlobalProtect), CVE-2024-24919 (Check Point VPN), and CVE-2022-30190 (Microsoft Follina). Broader targeting has affected SonicWall, Cisco ASA, F5 BIG-IP, Fortinet FortiGate, Sophos SSL VPN, Ivanti Connect Secure, and Microsoft Outlook Web Access.
What tools does RedNovember use? The observed toolset includes Pantegana (Go-based backdoor), LESLIELOADER (Go-based loader), SparkRAT (open-source remote administration tool), and Cobalt Strike (commercial red-team framework).
What is Pantegana? Pantegana is an open-source, Go-based, cross-platform backdoor. Reported capabilities include HTTPS command-and-control, system fingerprinting, command execution, file upload, and file download.
Why does RedNovember target VPNs and firewalls? Edge devices are internet-facing, hold high privilege, sit in the traffic path, and often have limited security telemetry. They provide scalable initial access to large numbers of organizations at lower detection risk than compromising internal endpoints individually.
Does RedNovember target aerospace and space companies? Yes. Recorded Future documented reconnaissance and targeting activity against U.S. defense industry organizations, likely compromise of at least two U.S. defense contractors, targeting of European aerospace and manufacturing organizations, and communications activity involving European space research entities.
How does RedNovember steal data? Recorded Future observed Pantegana capable of file upload from compromised hosts. Microsoft’s documentation of the overlapping Storm-2077 activity describes credential harvesting from compromised endpoints, session token replay against cloud environments, creation of attacker-controlled applications with mail-read rights, and email exfiltration through legitimate cloud applications including eDiscovery tools.
How can organizations detect RedNovember? Detection opportunities span the attack chain: edge exploitation attempts and configuration anomalies, known C2 infrastructure and beacon patterns, identity anomalies including token replay and unusual OAuth activity, and data-movement anomalies including bulk downloads and first-time external transfer destinations.
How can companies protect sensitive files after an edge-device compromise? Once perimeter defense has failed, protection depends on data-layer controls: least privilege access, data classification, controlled file transfer channels with authentication and audit trails, egress monitoring, restricted transfer destinations, and file scanning at ingestion. These controls limit what a compromised identity can access and remove even when initial access succeeds.
TL;DR: The OpenAI-Hugging Face breach wasn't a sci-fi scenario. AI agents used credential discovery, lateral…
In February 2025, cybersecurity firm Hudson Rock published research that cut through a lot of…
The OpenAI Breach Was a Data Movement Failure: What It Means for How Your Business…
Running Aspera in the cloud is increasingly becoming our customers’ preferred deployment method. While there is always a…
The Scale of Black Hat and Why this Show Matters We were on the floor…
TL;DR: Buying Aspera is the easy part. The value comes from configuring it correctly. A…