RedNovember is a Chinese state-sponsored cyberespionage threat actor active since at least 2024 and also tracked as Storm-2077 and TAG-100. The group conducts intelligence collection aligned with Chinese strategic and geopolitical interests, including operations timed around military exercises, diplomatic activity, and other events of interest to Beijing. Its victimology spans government, diplomatic, defense, aerospace, telecommunications, technology, legal, manufacturing, energy, financial, and research organizations across multiple regions. RedNovember is notable for rapidly exploiting newly disclosed vulnerabilities in internet-facing edge infrastructure rather than relying primarily on publicly reported zero-days. Reported initial access tradecraft includes targeting perimeter appliances, VPN gateways, firewalls, Outlook Web Access, and other externally exposed enterprise systems. The actor has been associated with compromises of edge devices from multiple major vendors as well as collaboration and email platforms. Microsoft has also reported phishing-based credential acquisition and subsequent abuse of cloud applications for email theft. Post-compromise, RedNovember uses a mix of commodity, open-source, and custom tooling. Reported tooling includes the Go-based Pantegana backdoor or command-and-control framework, Cobalt Strike, SparkRAT, and LESLIELOADER used to deploy SparkRAT. Observed capabilities include reconnaissance, credential theft, persistence, command execution, file transfer, and long-term access to victim environments. Reporting also indicates use of living-off-the-land techniques and cloud email collection methods, including abuse of administrative access and mail-reading application permissions. The group has targeted and in some cases likely compromised high-value organizations globally, with especially prominent reporting involving the United States, Taiwan, South Korea, and Panama. Victims have included government ministries, intergovernmental organizations, defense contractors, aerospace entities, telecommunications providers, research institutions, law firms, manufacturers, financial institutions, and oil and gas companies. Multiple assessments characterize RedNovember as a patient espionage actor focused on scalable access through exposed edge systems and follow-on intelligence collection rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected China state-sponsored espionage cluster targeting global government and private-sector organizations; reported using Pantegana and Cobalt Strike.
RedNovember is a Chinese government-sponsored espionage group known for targeting defense, electronics, and manufacturing companies, likely for the purposes of intellectual property theft and long-term espionage. While there is no public evidence of them specifically targeting robotics firms yet, their modus operandi aligns with targeting sectors prioritized in China's five-year plans, which now include AI and smart robotics.
Forecast-focused discussion of RedNovember’s likely evolution from PoC-driven N-day exploitation of edge devices (VPN/firewall gateways) toward potential zero-day use in 2026; notes attribution/rebranding risk and emphasizes edge-appliance stealth access as the operational objective.
RedNovember is a China-nexus espionage threat actor known for targeting edge devices using N-day vulnerabilities and public proof-of-concept exploits, with a focus on government, defense, and technology organizations. While their tradecraft has primarily relied on exploiting known vulnerabilities, there is a plausible risk they may pivot to using zero-day exploits, following the precedent set by other China-nexus groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.