RedNovember is a Chinese state-sponsored cyberespionage group previously tracked as TAG-100, also rendered TAG100, whose activity overlaps with Microsoft's Storm-2077 cluster. RedNovember has been observed since at least mid-2024; the overlapping Storm-2077 activity dates to January 2024. Its operations support intelligence collection aligned with Chinese geopolitical and military interests. It targets government ministries, diplomatic entities, intergovernmental organizations, defense contractors, aerospace organizations, manufacturers, technology companies, telecommunications providers, financial institutions, law firms, and energy companies. Its global targeting includes the United States, Taiwan, South Korea, Panama, and Fiji, with additional operations across Europe, Asia, Africa, and the Americas. The group emphasizes reconnaissance and rapid exploitation of newly disclosed vulnerabilities in internet-facing VPN gateways, firewalls, and other perimeter appliances, frequently acting soon after public proof-of-concept exploits become available. Targeted products include Cisco ASA, F5 BIG-IP, Fortinet FortiGate, Ivanti Connect Secure, Palo Alto Networks GlobalProtect, SonicWall, Sophos, and Check Point gateways. It also targets Outlook Web Access, Zimbra, and 3CX environments. RedNovember uses Pantegana, Cobalt Strike, SparkRAT, and Go-based LESLIELOADER variants for command and control and post-exploitation. Its tooling supports cross-platform access, file transfer, system fingerprinting, and interactive command execution. Commercial VPN services and obfuscation support operational concealment, while compromised perimeter systems provide persistent access to sensitive networks. The overlapping Storm-2077 cluster uses phishing to steal credentials, harvests additional credentials from compromised endpoints, and accesses cloud email environments for intelligence collection. Observed email-theft techniques include abusing legitimate eDiscovery applications and creating applications with mail-read permissions after obtaining administrative access. RedNovember has conducted extensive reconnaissance against Panamanian government organizations and Taiwanese scientific research infrastructure, alongside targeting of US defense and aerospace entities. Its operations emphasize broad intelligence requirements and sustained access rather than ransomware or financially motivated extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected China state-sponsored espionage cluster targeting global government and private-sector organizations; reported using Pantegana and Cobalt Strike.
RedNovember is a Chinese government-sponsored espionage group known for targeting defense, electronics, and manufacturing companies, likely for the purposes of intellectual property theft and long-term espionage. While there is no public evidence of them specifically targeting robotics firms yet, their modus operandi aligns with targeting sectors prioritized in China's five-year plans, which now include AI and smart robotics.
Forecast-focused discussion of RedNovember’s likely evolution from PoC-driven N-day exploitation of edge devices (VPN/firewall gateways) toward potential zero-day use in 2026; notes attribution/rebranding risk and emphasizes edge-appliance stealth access as the operational objective.
RedNovember is a China-nexus espionage threat actor known for targeting edge devices using N-day vulnerabilities and public proof-of-concept exploits, with a focus on government, defense, and technology organizations. While their tradecraft has primarily relied on exploiting known vulnerabilities, there is a plausible risk they may pivot to using zero-day exploits, following the precedent set by other China-nexus groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.