Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

RedNovember Hackers Targeting Government and Tech Organizations to Install Backdoor

Recorded Future’s Insikt Group has identified a cyber-espionage campaign known as TAG-100, using the Go-based backdoor Pantegana, targeting high-profile governmental, intergovernmental, and private organizations globally. This campaign is now attributed…

Recorded Future’s Insikt Group has identified a cyber-espionage campaign known as TAG-100, using the Go-based backdoor Pantegana, targeting high-profile governmental, intergovernmental, and private organizations globally. This campaign is now attributed to a Chinese state-sponsored threat actor, RedNovember.

Between June 2024 and July 2025, RedNovember expanded its operations to target perimeter appliances and VPN solutions, employing Pantegana and Cobalt Strike to maintain persistence. Likely victims include ministries of foreign affairs in Central and Southeast Asia, a state security organization in Africa, a European governmental directorate, two U.S. defense contractors, a European engine manufacturer, and a trade-focused intergovernmental body in Southeast Asia.

RedNovember utilizes open-source and commodity C2 frameworks, including Pantegana, Cobalt Strike, and SparkRAT, for reconnaissance, initial access, and potential compromise. They have extended their targeting to the U.S. Defense Industrial Base and European space and aerospace organizations through spearphishing and exploitation campaigns. Edge devices such as firewalls, VPNs, load balancers, and email servers serve as primary initial access vectors.

In April 2025, RedNovember conducted a focused campaign against Ivanti Connect Secure VPN appliances, targeting entities such as a major U.S. newspaper and a specialized engineering and military contractor. Several intrusions aligned with geopolitical events significant to China, such as military drills around Taiwan in December 2024 and U.S. diplomatic visits to Panama in April 2025.

This campaign is now attributed to a Chinese state-sponsored threat actor, RedNovember.
Brooke Sanders · Thehackingpost

Previously referred to as TAG-100, RedNovember exploits internet-facing devices to gain large-scale initial footholds, subsequently using Pantegana and Cobalt Strike for post-exploitation activities. The use of publicly available PoC exploits and open-source backdoors serves to lower operational costs and obscure attribution.

RedNovember’s victims span various sectors, including government, defense, aerospace, legal, and technology. Specific incidents include:

A Panamanian government-wide reconnaissance wave in April 2025, scanning over 30 ministries following U.S. diplomatic engagements. December 2024 activities targeting Taiwan Air Force-related infrastructure during China’s military exercises around the island. Multiple U.S. DIB and space research entities experiencing port scans and VPN exploit attempts. Compromise of a Taiwanese IT company and U.K.-based defense contractors via SonicWall SSL VPN and F5 BIG-IP appliances.

Advertisement

Organizations should incorporate threat intelligence to detect Pantegana and SparkRAT C2 domains in real time, prioritize patching high-risk RCE vulnerabilities in perimeter devices, and enforce strict access controls on VPN and firewall management interfaces. Network segmentation, multi-factor authentication, and enhanced logging on edge devices are crucial for detecting and responding to post-exploitation activities.

RedNovember’s ongoing expansion across geographies and sectors highlights persistent vulnerabilities in internet-facing appliances. Its reliance on open-source frameworks facilitates rapid scaling of campaigns, while the intermittent use of commodity tools suggests a flexible operational posture. As new exploits and PoC code become available, state-sponsored actors like RedNovember are likely to continue targeting edge devices aggressively. A defense-in-depth strategy will be essential to prevent future intrusions.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories