HomeSecurityRedNovember breached critical infrastructure worldwide

RedNovember breached critical infrastructure worldwide

A Chinese state-backed hacking group known as RedNovemberconducted a global espionage campaign targeting critical infrastructure between June 2024 and July 2025, breaching defense contractors, government agencies, and large corporations while exploiting vulnerabilities faster than organizations could implement security patches.

See also: BRICKSTORM: Chinese hackers had access to American companies for a year

RedNovember

The attacks included breaches of at least two US defense contractors and more than 30 Panamanian government agencies, as part of a systematic targeting of the US, Europe, Asia and South America, according to cybersecurity firm Recorded Future.

The threat group used the Go-based Pantegana backdoor , Cobalt Strike and SparkRAT to maintain persistent network access after exploiting vulnerabilities in enterprise devices, the researchers said in the report. Recorded Future’s Insikt Group had previously tracked the activity under the name TAG-100 before attributing it to Chinese state-backed enterprises.

Microsoft is also tracking overlapping activity from this group as Storm-2077. RedNovember systematically targeted internet-facing devices that form the backbone of enterprise network security, successfully compromising VPN appliances , Ivanti Connect Secure appliances, Cisco Adaptive Security Appliances, F5 BIG-IP systems, Sophos SSL VPN products and Fortinet FortiGate firewalls, the researchers found.

See also: Salt Typhoon attacks telecommunications infrastructure

RedNovember breached critical infrastructure worldwide

Hackers exploited both newly disclosed vulnerabilities and older weaknesses that organizations had not patched. RedNovember breached two U.S. defense contractors in April 2025 using vulnerabilities CVE-2023-46805 and CVE-2024-21887 in Ivanti devices — vulnerabilities for which there were patches since January 2024, the report says.

A European engine manufacturer that produces aerospace components was compromised through a SonicWall VPN appliance, while multiple law firms were victimized through compromised network devices, researchers documented. RedNovember demonstrated the ability to exploit recently disclosed vulnerabilities faster than most organizations could apply patches, the researchers found.

Rather than developing custom malware, RedNovember relied heavily on publicly available tools, including the Pantegana backdoor, the Cobalt Strike penetration testing framework and the SparkRAT remote access tool, all written in the Go programming language, the researchers found. The hackers used variants of the LESLIELOADER to deploy SparkRAT on compromised systems, with samples first detected in March 2024, according to the analysis. RedNovember also exploited legitimate services, including vulnerability scanning tools such as PortSwigger’s Burp Suite and VPN services including Cloudflare’s ExpressVPN and Warp, to manage its infrastructure.

See also: TA415 uses Google Sheets & Calendar for C2 communications

RedNovember breached critical infrastructure worldwide

The group heavily targeted organizations in the U.S., Taiwan and South Korea, while also conducting surveillance of government agencies in Panama and targeting entities in Europe, Africa, Central Asia and Southeast Asia, the report says. The hackers maintained persistent access to compromised networks for months, with some breaches lasting from July 2024 to March 2025, according to the research.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS