RedNovember Hackers Targeting Government and Tech Organizations to Install Backdoor
Recorded Future’s Insikt Group has identified a cyber-espionage campaign known as TAG-100, using the Go-based backdoor Pantegana, targeting high-profile governmental, intergovernmental, and private organizations globally. This campaign is now attributed…
Recorded Future’s Insikt Group has identified a cyber-espionage campaign known as TAG-100, using the Go-based backdoor Pantegana, targeting high-profile governmental, intergovernmental, and private organizations globally. This campaign is now attributed to a Chinese state-sponsored threat actor, RedNovember.
Between June 2024 and July 2025, RedNovember expanded its operations to target perimeter appliances and VPN solutions, employing Pantegana and Cobalt Strike to maintain persistence. Likely victims include ministries of foreign affairs in Central and Southeast Asia, a state security organization in Africa, a European governmental directorate, two U.S. defense contractors, a European engine manufacturer, and a trade-focused intergovernmental body in Southeast Asia.
RedNovember utilizes open-source and commodity C2 frameworks, including Pantegana, Cobalt Strike, and SparkRAT, for reconnaissance, initial access, and potential compromise. They have extended their targeting to the U.S. Defense Industrial Base and European space and aerospace organizations through spearphishing and exploitation campaigns. Edge devices such as firewalls, VPNs, load balancers, and email servers serve as primary initial access vectors.
In April 2025, RedNovember conducted a focused campaign against Ivanti Connect Secure VPN appliances, targeting entities such as a major U.S. newspaper and a specialized engineering and military contractor. Several intrusions aligned with geopolitical events significant to China, such as military drills around Taiwan in December 2024 and U.S. diplomatic visits to Panama in April 2025.
This campaign is now attributed to a Chinese state-sponsored threat actor, RedNovember.
Previously referred to as TAG-100, RedNovember exploits internet-facing devices to gain large-scale initial footholds, subsequently using Pantegana and Cobalt Strike for post-exploitation activities. The use of publicly available PoC exploits and open-source backdoors serves to lower operational costs and obscure attribution.
RedNovember’s victims span various sectors, including government, defense, aerospace, legal, and technology. Specific incidents include:
A Panamanian government-wide reconnaissance wave in April 2025, scanning over 30 ministries following U.S. diplomatic engagements. December 2024 activities targeting Taiwan Air Force-related infrastructure during China’s military exercises around the island. Multiple U.S. DIB and space research entities experiencing port scans and VPN exploit attempts. Compromise of a Taiwanese IT company and U.K.-based defense contractors via SonicWall SSL VPN and F5 BIG-IP appliances.
Organizations should incorporate threat intelligence to detect Pantegana and SparkRAT C2 domains in real time, prioritize patching high-risk RCE vulnerabilities in perimeter devices, and enforce strict access controls on VPN and firewall management interfaces. Network segmentation, multi-factor authentication, and enhanced logging on edge devices are crucial for detecting and responding to post-exploitation activities.
RedNovember’s ongoing expansion across geographies and sectors highlights persistent vulnerabilities in internet-facing appliances. Its reliance on open-source frameworks facilitates rapid scaling of campaigns, while the intermittent use of commodity tools suggests a flexible operational posture. As new exploits and PoC code become available, state-sponsored actors like RedNovember are likely to continue targeting edge devices aggressively. A defense-in-depth strategy will be essential to prevent future intrusions.
Based on reporting by GBHackers.
