HomeSecurityChinese Hackers RedNovember Target Global Governments

Chinese Hackers RedNovember Target Global Governments

A suspicious set of cyberespionage activities previously identified as targeting global government and private organizations in Africa, Asia, North America, South America, and Oceania has been identified as the RedNovember group, which is backed by the Chinese state.

See also: US: Chinese hackers breached up to 115 million payment cards

RedNovember

Recorded Future, which was tracking activity under the alias TAG-100, was the one that discovered the RedNovember group. It is also being tracked by Microsoft as Storm-2077.

Some of the potential new victims of the threat include a foreign ministry in Central Asia, a state security agency in Africa, a European government department, and a Southeast Asian government. The group is also believed to have breached at least two US defense contractors, a European engine manufacturer, and a trade-oriented intergovernmental cooperation organization in Southeast Asia.

RedNovember was first documented by Recorded Future over a year ago, describing the use of the Pantegana and Spark RAT after exploiting known vulnerabilities in various internet-exposed perimeter devices from Check Point (CVE-2024-24919), Cisco, Citrix, F5, Fortinet, Ivanti, Palo Alto Networks (CVE-2024-3400) , and SonicWall for initial access.

The focus on targeting security solutions such as VPNs, firewalls, load balancers, virtualization infrastructure , and email servers reflects a trend that has been increasingly adopted by other Chinese state-backed hacking groups to infiltrate networks of interest and maintain their presence for extended periods.

See also: Chinese hackers attack Windows systems with Ghost RAT and PhantomNet

Chinese Hackers RedNovember Target Global Governments

A notable element of the RedNovember team's technique is the use of Pantegana and Spark RATs, two open source tools. The adoption is likely an attempt to reuse existing programs to their advantage and confuse attribution efforts, a characteristic of spyware actors.

The attacks also include using a variant of the publicly available Go-based loader LESLIELOADER to launch the Spark RAT or Cobalt Strike Beacons on compromised devices.

RedNovember is reportedly using VPN services such as ExpressVPN and Warp VPN to manage and connect to two sets of servers used to exploit devices exposed to the internet and communicate with Pantegana, Spark RAT, and Cobalt Strike, another legitimate program that has been widely abused by malicious actors.

Between June 2024 and May 2025, much of the hacking group's targeting efforts have focused on Panama, the U.S., Taiwan, and South Korea. In April 2025, it was found to be targeting Ivanti Connect Secure associated with a newspaper and an engineering and military contractor, both based in the U.S.

See also: TA415 uses Google Sheets & Calendar for C2 communications

Chinese Hackers RedNovember Target Global Governments

Recorded Future also stated that the RedNovember group is likely targeting Microsoft Outlook Web Access (OWA) portals belonging to a South American country ahead of that country's state visit to China.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS